CVE-2026-56786Disclosure(rtklib / rtklib)

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch rtklib rtklib systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to clamp length counters to destination buffer size, allowing up to 191-byte overflow into fixed 64-byte descriptor fields. An attacker controlling an NTRIP or serial RTCM3 correction stream can craft a valid CRC-bearing type-1033 message to corrupt adjacent rtcm_t object members, potentially achieving arbitrary code execution or denial of service.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rtklib

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-25); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
rtklib

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-06-25: 2Mentions · 2026-06-26: 2Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-06-26: 1Technical Details · 2026-06-25: 2Technical Details · 2026-06-26: 206-2506-26
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets3 URLs
Full discourse4 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-56786 — CVSS 9.8/10 ██████████ RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to clamp... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/dM6NHeJtnX

    Post summary

    CVE‑2026‑56786 is an out‑of‑bounds write in RTKLIB v2.4.3 with critical severity, and a patch is now available. No PoC, exploit code, or active exploitation evidence is provided.

    1000088
    60 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    #CVE-2026-56786 - Critical #OOB write in #Rtklib up to 2.4.3. decode_type1033 overflow can lead to #RCE or #DoS via crafted RTCM3 stream. #CVSS 9.8. Isolate or disable NTRIP/serial inputs immediately. #CVEAlert #infosec #CyberSecurity #cybersecuritytips More: https://www.valtersit.com/cve/CVE-2026-56786/

    Post summary

    The tweet announces a critical out‑of‑bounds write in Rtklib that could enable RCE or DoS and advises disabling NTRIP/serial inputs as a mitigation, without providing a PoC or exploit details.

    0000077
    967 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - RTKLIB RTCM3 Type-1033 OOB Write in decode_type1033 (CVE-2026-56786) RTKLIB through 2.4.3 is vulnerable to an out-of-bounds write in the RTCM3 message parser, specifically the decode_type1033 function handling type-1033 descriptor fields. The root cause is improper bounds checking: length counters aren’t clamped to the fixed 64-byte destination buffers, allowing up to ~191 bytes to overflow into adjacent rtcm_t object members. An attacker who can control the incoming RTCM3 correction stream (e.g., via a malicious NTRIP caster or tampered serial feed) can send a crafted type-1033 message with a valid CRC to reliably trigger the overwrite. Successful exploitation can corrupt process memory leading to remote code execution in the GNSS processing context or a crash/denial of service, potentially disrupting positioning and downstream systems relying on it. 👉 Affected: RTKLIB <= 2.4.3 | Upgrade to No fix yet - treat as suspicious

    Post summary

    The post announces CVE-2026-56786 in RTKLIB, detailing an out‑of‑bounds write vulnerability and potential RCE, but provides no PoC, exploit code, or evidence of active exploitation.

    0000078
    231 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-56786 Out-of-Bounds Write Vulnerability in RTKLIB Through 2.4.3 decode_... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-56786 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces CVE-2026-56786 as an out-of-bounds write in RTKLIB up to version 2.4.3, linking to a vulnerability details page for further information.

    0000089
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apprtklibrtklib---

Explore more