← Vulnerability feed

Vulnerability record · CVE-2025-53470 · published 10 January 2026

CVE-2025-53470: Apache nimble out-of-bounds read vulnerability

Apache · Nimble

Out-of-bounds Read vulnerability in Apache NimBLE HCI H4 driver. Specially crafted HCI event could lead to invalid memory read in H4 driver. This issue affects Apache NimBLE: through 1.8.  This issue requires a broken or bogus Bluetooth controller and thus severity is considered low. Users are recommended to upgrade to version 1.9, which fixes the issue.

3.1 CVSS 3.1 Low EPSS 0.34% · top 75.4% CWE-125 · Out-of-bounds read
3.1CVSS 3.1 base score
0.34%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Out-of-bounds Read vulnerability in Apache NimBLE HCI H4 driver. Specially crafted HCI event could lead to invalid memory read in H4 driver. This issue affects Apache NimBLE: through 1.8.  This issue requires a broken or bogus Bluetooth controller and thus severity is considered low. Users are recommended to upgrade to version 1.9, which fixes the issue.

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-53470 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-45813Apache nimble out-of-bounds write vulnerabilityOut-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper validation when parsing BASS servic…EPSS 0.53%8.1CVE-2025-62235Apache nimble authentication bypass by spoofing vulnerabilityAuthentication Bypass by Spoofing vulnerability in Apache NimBLE. Receiving specially crafted Security Request could lead to removal of original bond…EPSS 0.38%7.5CVE-2026-45815Apache nimble vulnerabilityReachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigge…EPSS 1.0%7.5CVE-2026-45816Apache nimble null pointer dereference vulnerabilityNULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asserts (otherwise assert would tri…EPSS 1.0%7.5CVE-2026-45811Apache nimble classic buffer overflow vulnerabilityBuffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket transport did not check whether…EPSS 0.48%7.5CVE-2025-52435Apache nimble vulnerabilityJ2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE. Improper handling of Pause Encryption procedure on Link L…EPSS 0.23%7.5CVE-2025-53477Apache nimble null pointer dereference vulnerabilityNULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command TX buffer could lead to NULL po…EPSS 0.80%7.5CVE-2024-51569Apache nimble out-of-bounds read vulnerabilityOut-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access whe…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2025-53470), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.