← Vulnerability feed

Vulnerability record · CVE-2026-45812 · published 24 July 2026

CVE-2026-45812: Apache nimble vulnerability

Apache · Nimble

Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report HCI event. When a single HCI advertising report event bundles multiple reports, NimBLE miscalculated the offset to the next report. This can cause the host to read past the end of the buffer and deliver a GAP event with bogus data to the application. Severity is low: NimBLE's own controller never batches multiple reports into one event, so this only matters when NimBLE's host is paired with a third-party controller that does. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.

6.5 CVSS 3.1 Medium EPSS 0.69% · top 49.0% CWE-131 · CWE-131
6.5CVSS 3.1 base score
0.69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
27 Jul 2026Last modified by NVD

Description

Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report HCI event. When a single HCI advertising report event bundles multiple reports, NimBLE miscalculated the offset to the next report. This can cause the host to read past the end of the buffer and deliver a GAP event with bogus data to the application. Severity is low: NimBLE's own controller never batches multiple reports into one event, so this only matters when NimBLE's host is paired with a third-party controller that does. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-45812 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-45813Apache nimble out-of-bounds write vulnerabilityOut-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper validation when parsing BASS servic…EPSS 0.53%8.1CVE-2025-62235Apache nimble authentication bypass by spoofing vulnerabilityAuthentication Bypass by Spoofing vulnerability in Apache NimBLE. Receiving specially crafted Security Request could lead to removal of original bond…EPSS 0.38%7.5CVE-2026-45815Apache nimble vulnerabilityReachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigge…EPSS 1.0%7.5CVE-2026-45816Apache nimble null pointer dereference vulnerabilityNULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asserts (otherwise assert would tri…EPSS 1.0%7.5CVE-2026-45811Apache nimble classic buffer overflow vulnerabilityBuffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket transport did not check whether…EPSS 0.48%7.5CVE-2025-52435Apache nimble vulnerabilityJ2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE. Improper handling of Pause Encryption procedure on Link L…EPSS 0.23%7.5CVE-2025-53477Apache nimble null pointer dereference vulnerabilityNULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command TX buffer could lead to NULL po…EPSS 0.80%7.5CVE-2024-51569Apache nimble out-of-bounds read vulnerabilityOut-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access whe…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2026-45812), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.