A critical vulnerability tracked as CVE-2026-56786 affects RTKLIB through version 2.4.3. The flaw is an out-of-bounds write in the decode_type1033 function, where length counters are not properly clamped to destination buffer sizes. A crafted RTCM3 type-1033 message with a valid CRC can trigger an overflow of up to 191 bytes into fixed 64-byte descriptor fields, corrupting adjacent members of the rtcm_t object.
The issue is considered remotely exploitable when an attacker can control an NTRIP or serial RTCM3 correction stream, potentially leading to arbitrary code execution or denial of service. The vulnerability has been rated 9.8 under CVSS 3.1 and 9.3 under CVSS 4.0. Recommended mitigations include updating RTKLIB, applying the vendor patch for decode_type1033, validating buffer lengths before writes, and sanitizing input length counters.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
A critical out-of-bounds write vulnerability affecting RTKLIB through version 2.4.3 was disclosed as CVE-2026-56786. The flaw in decode_type1033 can be triggered with a crafted RTCM3 type-1033 message and may enable denial of service or arbitrary code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcevulncheck.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.