← Vulnerability feed

Vulnerability record · CVE-2026-45811 · published 24 July 2026

CVE-2026-45811: Apache nimble classic buffer overflow vulnerability

Apache · Nimble

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer overflow. Severity is low: exploitation requires either a misconfigured pool size or a malicious/compromised controller on the other end of the HCI socket link, not over-the-air Bluetooth access. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.

7.5 CVSS 3.1 High EPSS 0.48% · top 60.9% CWE-120 · Classic buffer overflow
7.5CVSS 3.1 base score
0.48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
27 Jul 2026Last modified by NVD

Description

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer overflow. Severity is low: exploitation requires either a misconfigured pool size or a malicious/compromised controller on the other end of the HCI socket link, not over-the-air Bluetooth access. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-45811 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-45813Apache nimble out-of-bounds write vulnerabilityOut-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper validation when parsing BASS servic…EPSS 0.53%8.1CVE-2025-62235Apache nimble authentication bypass by spoofing vulnerabilityAuthentication Bypass by Spoofing vulnerability in Apache NimBLE. Receiving specially crafted Security Request could lead to removal of original bond…EPSS 0.38%7.5CVE-2026-45815Apache nimble vulnerabilityReachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigge…EPSS 1.0%7.5CVE-2026-45816Apache nimble null pointer dereference vulnerabilityNULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asserts (otherwise assert would tri…EPSS 1.0%7.5CVE-2025-52435Apache nimble vulnerabilityJ2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE. Improper handling of Pause Encryption procedure on Link L…EPSS 0.23%7.5CVE-2025-53477Apache nimble null pointer dereference vulnerabilityNULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command TX buffer could lead to NULL po…EPSS 0.80%7.5CVE-2024-51569Apache nimble out-of-bounds read vulnerabilityOut-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access whe…EPSS 1.2%7.5CVE-2024-24746Apache nimble vulnerabilityLoop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE.  Specially crafted GATT operation can cause infinite loop in G…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2026-45811), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.