๐Ÿ” CVE Alert

CVE-2026-45811

UNKNOWN 0.0

Apache NimBLE: Buffer overflow in socket HCI transport

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer overflow. Severity is low: exploitation requires either a misconfigured pool size or a malicious/compromised controller on the other end of the HCI socket link, not over-the-air Bluetooth access. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.

CWE CWE-120
Vendor apache software foundation
Product apache nimble
Published Jul 24, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache nimble

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache nimble are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache NimBLE
0 โ‰ค 1.9.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/apache/mynewt-nimble/commit/dcc4e4f026109eecd507de9479bb5019306a4a41 lists.apache.org: https://lists.apache.org/thread/5mkz68y1py0o6zmxtc3l1o8grtrb78m0

Credits

๐Ÿ” Yicheng Yang, Secsys Lab, Fudan University