🔐 CVE Alert

CVE-2026-45815

UNKNOWN 0.0

Apache NimBLE: Remote reachable assertion in ATT Read Multiple Variable Response handler

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser. Severity is medium as this requires DUT to first send ATT Read Multiple Variable Request. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.

CWE CWE-617
Vendor apache software foundation
Product apache nimble
Published Jul 24, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache nimble

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache nimble are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Apache Software Foundation / Apache NimBLE
0 ≤ 1.9.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/apache/mynewt-nimble/commit/fae6a4874309ba0175d2c444e20f8a6bde007425 lists.apache.org: https://lists.apache.org/thread/3d09hgo5zmm7dnryst3tb9857hk1bbos

Credits

🔍 Amemoyoi https://github.com/Amemoyoi