Rtklib Rtklib — CVE-2026-56786 (Critical)
Summary
RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to clamp length counters to destination buffer size, allowing up to 191-byte overflow into fixed 64-byte descriptor fields. An attacker controlling an NTRIP or serial RTCM3 correction stream can craft a valid CRC-bearing type-1033 message to corrupt adjacent rtcm_t object members, potentially achieving arbitrary code execution or denial of service.
Why it matters
This CVE carries a CRITICAL severity rating (CVSS 9.8) in Rtklib Rtklib. Patch or mitigate promptly. EPSS percentile: 32%.
Operator check
Review CVE-2026-56786 in your asset inventory. Apply patches per vendor guidance and verify Rtklib is not exposed. CVSS score: 9.8. EPSS probability: 0.4%; percentile: 32%.
Sources
PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.