CVE-2026-45811

HIGH CVSS 3.1: 7.5 EPSS 0.34%
Updated Jul 27, 2026
Apache
Parameter Value
CVSS 7.5 (HIGH)
Affected Versions before 1.10.0
Fixed In 1.10.0
Type CWE-120 (Buffer Copy without Checking Size)
Vendor Apache
Public PoC No

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket transport did not check whether a received HCI event would fit the configured event pool before copying it, allowing a buffer overflow. Severity is low: exploitation requires either a misconfigured pool size or a malicious/compromised controller on the other end of the HCI socket link, not over-the-air Bluetooth access.

This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.

Attack Parameters

Attack Vector
Adjacent
Requires local network access
Attack Complexity
High
Difficult to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Apache Nimble
cpe:2.3:a:apache:nimble:*:*:*:*:*:*:*:*
1.10.0