CVE-2026-45811
Apache NimBLE: Buffer overflow in socket HCI transport
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer overflow. Severity is low: exploitation requires either a misconfigured pool size or a malicious/compromised controller on the other end of the HCI socket link, not over-the-air Bluetooth access. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.
| CWE | CWE-120 |
| Vendor | apache software foundation |
| Product | apache nimble |
| Published | Jul 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache nimble
Be the first to know when new unknown vulnerabilities affecting apache software foundation apache nimble are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Apache Software Foundation / Apache NimBLE
0 โค 1.9.0
References
Credits
๐ Yicheng Yang, Secsys Lab, Fudan University