CVE-2026-42996: JS8CALL

Critical severity, CVSS 10.0. EPSS: 0.6% chance of exploitation in the next 30 days.

JS8Call through 2.3.1 and JS8Call-improved before 3.0 have a stack-based buffer overflow via a radio transmission of @APRSIS GRID followed by a long Maidenhead locator. This occurs in grid2deg in APRSISClient.cpp.

Affected products

Published 2026-05-01. Last modified 2026-06-17.