CVE-2026-56770Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

libais through 0.15 VdmStream::AddLine uses an unchecked sentinel value as a vector index when processing AIS sentences with empty or out-of-range sequential message IDs. Remote attackers can crash services or vessel systems by sending crafted AIVDM sentences over VHF marine radio or IP feeds, causing out-of-bounds memory access and potential corruption.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-129

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-06-25); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-25: 1Mentions · 2026-06-26: 1Patch / Workaround · 2026-06-26: 1Technical Details · 2026-06-25: 1Technical Details · 2026-06-26: 106-2506-26
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-56770 - Out-of-bounds access in Libais <=0.15. Remote attackers can crash systems via crafted #AIS sentences. #CVSS 7.5. No patch available. Mitigate immediately. #100daysofcybersecurity #infosec #maritime #hackers #USA More detailed info: https://www.valtersit.com/cve/CVE-2026-56770

    Post summary

    An out‑of‑bounds access flaw in Libais 0.15 allows remote attackers to crash systems through crafted AIS sentences; no patch is available, so immediate mitigation is advised.

    00001138
    967 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-56770 Out-of-Bounds Memory Access in libais VdmStream AddLine Message Processing https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-56770

    Post summary

    The note announces CVE-2026-56770, noting an out-of-bounds memory access vulnerability in libais’s VdmStream AddLine processing, and directs readers to a external vulnerability details page.

    0000097
    4.1K followersView on X

Explore more