Malformed Character Encoding Vulnerability in Meshtastic Open Source Solution
CVE-2026-42566

7.5HIGH

Key Information:

Vendor

Meshtastic

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-42566?

Meshtastic, an open source mesh networking solution, suffers from a vulnerability that arises when a node advertises a User.long_name containing malformed character encoding. This issue can render other devices unusable when managed via the iOS app due to a failure in Bluetooth Low Energy (BLE) synchronization. If the User.long_name is corrupted, it causes the app to enter a fail/retry loop, leading to significant management difficulties for users. As the malformed name can propagate through the mesh, the impact can be extensive, affecting numerous users across varying geographical locations. Even routine buffer truncation can trigger this vulnerability, making it a concern for all users. Mitigations in version 2.7.23.b246bcd include improved input sanitization and regression tests, which help restore functionality to previously affected devices.

Affected Version(s)

firmware < 2.7.23.b246bcd

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.