Index: /tags/BNC_2.13.7/CHANGELOG.md
===================================================================
--- /tags/BNC_2.13.7/CHANGELOG.md	(revision 11043)
+++ /tags/BNC_2.13.7/CHANGELOG.md	(revision 11044)
@@ -1,4 +1,8 @@
 # Changelog
-## 2.13.7 (2026-31-07)
+## 2.13.7.1 (2026-09-24)
+- FIXED: a latent stack-overflow risk in RTCM3coDecoder: This is solved by ordering extra heap per active SSR co-decoder; prevents a reliable crash on macOS because of a small default stack for secondary threads of only ~512 KB
+- FIXED: RINEX version 3/4 filename generation from mountpoint names that are not conform to the RINEX naming convention: char 5-6 of the mountpoint name are only taken as monument/receiver digits, if they are actually digits. Otherwise falling back to "00".
+
+## 2.13.7 (2026-07-31)
 - ADDED: PPP-AR Algorithm description is now part of BNCs help contents
 - ADDED: L1C/B (RINEX code: '1E') in QZSS Signal ID Mapping
@@ -12,7 +16,7 @@
 - FIXED: SP3/Clock RINEX clock values produced by the Upload Corrections feature no longer depend on whether 'Center of Mass' is ticked, since that setting should only affect the uploaded SSR Broadcast Correction stream [(#210)](https://software.rtcm-ntrip.org/ticket/210)
 - FIXED: A timeout is added to allow a reonnect after an outage of Ntrip Version 2/2s streams
-- FIXED: "END OF EPOCH" entry in RINEX observation files is compleated by "COMMENT" 
-- CHANGED: prevention to extrapolate a orb/clk SSR correction far beyond its own declared update interval 
-- CHANGED: GLONASS postion integration fresh from the pristine, decoded TOC state rather than rolling _tt/_xv forward across repeated calls; prevents a crash in SSR upload 
+- FIXED: "END OF EPOCH" entry in RINEX observation files is compleated by "COMMENT"
+- CHANGED: prevention to extrapolate a orb/clk SSR correction far beyond its own declared update interval
+- CHANGED: GLONASS postion integration fresh from the pristine, decoded TOC state rather than rolling _tt/_xv forward across repeated calls; prevents a crash in SSR upload
 
 ## 2.13.6 (2026-05-05)
Index: /tags/BNC_2.13.7/src/RTCM3/RTCM3coDecoder.cpp
===================================================================
--- /tags/BNC_2.13.7/src/RTCM3/RTCM3coDecoder.cpp	(revision 11043)
+++ /tags/BNC_2.13.7/src/RTCM3/RTCM3coDecoder.cpp	(revision 11044)
@@ -97,4 +97,5 @@
   _providerID[2] = -1;
 
+  _stateSnapshot = new t_stateSnapshot;
   _ssrCorr = 0;
 
@@ -106,4 +107,5 @@
   delete _out;
   delete _ssrCorr;
+  delete _stateSnapshot;
   _IODs.clear();
   _orbCorrections.clear();
@@ -175,12 +177,9 @@
   while(_buffer.size()) {
 
-    struct SsrCorr::ClockOrbit clkOrbSav;
-    struct SsrCorr::CodeBias   codeBiasSav;
-    struct SsrCorr::PhaseBias  phaseBiasSav;
-    struct SsrCorr::VTEC       vTECSav;
-    memcpy(&clkOrbSav,     &_clkOrb,    sizeof(clkOrbSav)); // save state
-    memcpy(&codeBiasSav,   &_codeBias,  sizeof(codeBiasSav));
-    memcpy(&phaseBiasSav,  &_phaseBias, sizeof(phaseBiasSav));
-    memcpy(&vTECSav,       &_vTEC,      sizeof(vTECSav));
+    // save state
+    memcpy(&_stateSnapshot->clkOrb,    &_clkOrb,    sizeof(_clkOrb));
+    memcpy(&_stateSnapshot->codeBias,  &_codeBias,  sizeof(_codeBias));
+    memcpy(&_stateSnapshot->phaseBias, &_phaseBias, sizeof(_phaseBias));
+    memcpy(&_stateSnapshot->vTEC,      &_vTEC,      sizeof(_vTEC));
 
     int bytesused = 0;
@@ -190,8 +189,8 @@
 
     if      (irc <= -30) { // not enough data - restore state and exit loop
-      memcpy(&_clkOrb,    &clkOrbSav,    sizeof(clkOrbSav));
-      memcpy(&_codeBias,  &codeBiasSav,  sizeof(codeBiasSav));
-      memcpy(&_phaseBias, &phaseBiasSav, sizeof(phaseBiasSav));
-      memcpy(&_vTEC,      &vTECSav,      sizeof(vTECSav));
+      memcpy(&_clkOrb,     &_stateSnapshot->clkOrb,    sizeof(_clkOrb));
+      memcpy(&_codeBias,   &_stateSnapshot->codeBias,  sizeof(_codeBias));
+      memcpy(&_phaseBias,  &_stateSnapshot->phaseBias, sizeof(_phaseBias));
+      memcpy(&_vTEC,       &_stateSnapshot->vTEC,      sizeof(_vTEC));
       break;
     }
Index: /tags/BNC_2.13.7/src/RTCM3/RTCM3coDecoder.h
===================================================================
--- /tags/BNC_2.13.7/src/RTCM3/RTCM3coDecoder.h	(revision 11043)
+++ /tags/BNC_2.13.7/src/RTCM3/RTCM3coDecoder.h	(revision 11044)
@@ -74,4 +74,11 @@
   bool corrIsOutOfRange(const SsrCorr::ClockOrbit::SatData& coSat);
 
+  struct t_stateSnapshot {
+    SsrCorr::ClockOrbit clkOrb;
+    SsrCorr::CodeBias   codeBias;
+    SsrCorr::PhaseBias  phaseBias;
+    SsrCorr::VTEC       vTEC;
+  };
+
   std::ofstream*                        _out;
   QString                               _staID;
@@ -83,4 +90,5 @@
   SsrCorr::PhaseBias                    _phaseBias;
   SsrCorr::VTEC                         _vTEC;
+  t_stateSnapshot*                      _stateSnapshot;
   int                                   _providerID[3];
   e_type                                _type;
Index: /tags/BNC_2.13.7/src/bncversion.h
===================================================================
--- /tags/BNC_2.13.7/src/bncversion.h	(revision 11043)
+++ /tags/BNC_2.13.7/src/bncversion.h	(revision 11044)
@@ -3,5 +3,5 @@
 #define BNCVERSION_H
 
-#define BNCVERSION "2.13.7"
+#define BNCVERSION "2.13.7.1"
 #define BNCPGMNAME "BNC " BNCVERSION
 
