Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User.long_name that contains a malformed character encoding can render other radios unusable over BLE when managed through the iOS app. The malformed name does not need to be maliciously crafted — it can arise from ordinary buffer truncation and has been observed occurring naturally in the wild. At least one code path could place a null terminator in the middle of a multibyte sequence, leaving a malformed User.long_name in the node database. The problem surfaced downstream: the iOS app enforced encoding validation and therefore cannot parse a node database once it contains a poisoned entry. This caused BLE sync to enter a fail/retry loop, resulting in loss of control over the affected device. For a typical user managing their radio with the iOS app, the device becomes effectively unusable until the poisoned node ages out of the on-device database, or unless they have an alternate management path (e.g., the Python CLI, which can be used to identify and remove the offending entries manually). Because the malformed name propagates through the mesh, the temporary presence of a single affected node can degrade BLE management for iOS users across a wide geographical area for an extended period. Less technical users have no straightforward recovery path. Starting in version 2.7.23.b246bcd, the firmware has added input sanitization and regression tests demonstrating recovery for already-poisoned devices. The apps have also taken steps to ensure more graceful handling of malformed encoding sequences as well.
CVE-2026-42566
This high-severity CVE scores 7.5 under a secondary CVSS source (NVD's own analysis pending). EPSS exploit probability: 0.5%, top 60% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 7.5
- EG Score
- 7.5(medium)
- EG Risk
- 49(Track)EG Risk 49/100SSVC: Track
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity75% × 45%Exploitation0% × 40%Automatability100% × 15%Action: Routine — remediate on your standard cadence. - EPSS PROB
- 0%
- EPSS %ILE
- 40%
- KEV
- Not listed
Published
July 19, 2026
Last Modified
August 18, 2026
Advisory Details (2)
Auto-updated Jul 19, 2026commit 2cc13a1132d9 (meshtastic/firmware)
Fix landed in meshtastic/firmware commit 2cc13a1132d9 — awaiting tagged release
https://github.com/meshtastic/firmware/commit/2cc13a1132d94b66a9505e7f07ee2d3e83bd0c95Malformed encoding in User.long_name broadcast over LoRa causes client decode failure · Advisory · meshtastic/firmware · GitHub
https://github.com/meshtastic/firmware/security/advisories/GHSA-7ph5-2mjv-69h8Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 10× in last 7d / 54× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-08-30 02:42 UTCEG score recompute
- 2026-08-30 01:22 UTCEPSS rescore
- 2026-08-28 21:41 UTCEPSS rescore
- 2026-08-28 01:41 UTCEG score recompute
- 2026-08-27 14:25 UTCEPSS rescore
- 2026-08-26 22:12 UTCEG score recompute
- 2026-08-26 14:46 UTCEPSS rescore
- 2026-08-25 20:16 UTCEG score recompute
- 2026-08-25 13:49 UTCEPSS rescore
- 2026-08-24 19:01 UTCEG score recompute
- 2026-08-23 01:33 UTCEG score recompute
- 2026-08-23 00:19 UTCEPSS rescore
- 2026-08-22 00:41 UTCEG score recompute
- 2026-08-21 23:49 UTCEPSS rescore
- 2026-08-20 23:47 UTCEG score recompute
- 2026-08-20 22:55 UTCEPSS rescore
- 2026-08-19 22:55 UTCEG score recompute
- 2026-08-19 17:03 UTCEPSS rescore
- 2026-08-18 18:25 UTCEG score recompute
- 2026-08-18 13:48 UTCEPSS rescore
- 2026-08-17 21:05 UTCEG score recompute
- 2026-08-17 13:47 UTCEPSS rescore
- 2026-08-16 17:48 UTCEG score recompute
- 2026-08-16 14:56 UTCEPSS rescore
- 2026-08-16 05:20 UTCEG score recompute
Show 53 moreShow fewer
- 2026-08-16 02:14 UTCEPSS rescore
- 2026-08-15 04:29 UTCEG score recompute
- 2026-08-15 01:30 UTCEPSS rescore
- 2026-08-14 03:36 UTCEG score recompute
- 2026-08-13 22:00 UTCEPSS rescore
- 2026-08-12 14:18 UTCEG score recompute
- 2026-08-12 13:51 UTCEPSS rescore
- 2026-08-12 01:52 UTCEG score recompute
- 2026-08-11 13:43 UTCEPSS rescore
- 2026-08-11 00:55 UTCEG score recompute
- 2026-08-11 00:00 UTCEPSS rescore
- 2026-08-09 23:53 UTCEG score recompute
- 2026-08-09 13:46 UTCEPSS rescore
- 2026-08-08 23:01 UTCEG score recompute
- 2026-08-08 16:37 UTCEPSS rescore
- 2026-08-07 22:08 UTCEG score recompute
- 2026-08-06 21:16 UTCEG score recompute
- 2026-08-06 13:46 UTCEPSS rescore
- 2026-08-05 20:24 UTCEG score recompute
- 2026-08-05 19:17 UTCEPSS rescore
- 2026-08-04 19:31 UTCEG score recompute
- 2026-08-04 15:10 UTCEPSS rescore
- 2026-08-04 10:38 UTCEPSS rescore
- 2026-08-03 18:16 UTCEG score recompute
- 2026-08-03 10:36 UTCEPSS rescore
- 2026-08-02 04:57 UTCEG score recompute
- 2026-08-02 02:27 UTCEPSS rescore
- 2026-08-01 16:31 UTCEG score recompute
- 2026-08-01 04:16 UTCEPSS rescore
- 2026-07-31 03:09 UTCEG score recompute
- 2026-07-30 16:28 UTCEPSS rescore
- 2026-07-30 14:42 UTCEG score recompute
- 2026-07-30 02:07 UTCEG score recompute
- 2026-07-30 01:30 UTCEPSS rescore
- 2026-07-29 01:15 UTCEG score recompute
- 2026-07-28 15:36 UTCEPSS rescore
- 2026-07-28 00:23 UTCEG score recompute
- 2026-07-27 14:13 UTCEPSS rescore
- 2026-07-26 23:18 UTCEG score recompute
- 2026-07-26 14:54 UTCEPSS rescore
- 2026-07-26 14:54 UTCEPSS rescore
- 2026-07-26 10:50 UTCEG score recompute
- 2026-07-25 14:18 UTCEPSS rescore
- 2026-07-24 14:17 UTCEPSS rescore
- 2026-07-23 14:18 UTCEPSS rescore
- 2026-07-23 03:11 UTCEG score recompute
- 2026-07-22 23:55 UTCEG score recompute
- 2026-07-22 14:08 UTCEPSS rescore
- 2026-07-21 15:24 UTCEPSS rescore
- 2026-07-20 17:08 UTCEPSS rescore
- 2026-07-20 01:21 UTCEG score recompute
- 2026-07-19 23:38 UTCEG score recompute
- 2026-07-19 23:38 UTCMITRE cvelistV5first tracked
Frequently asked(5)
What is CVE-2026-42566?
When was CVE-2026-42566 disclosed?
Is CVE-2026-42566 actively exploited?
What is the CVSS score of CVE-2026-42566?
How do I remediate CVE-2026-42566?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-42566
Is Your Infrastructure Affected by CVE-2026-42566?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.