PT-2026-64282 · Apache · Apache Nimble

·

CVE-2026-45815

·

Published

2026-07-24

·

Updated

2026-07-27

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache NimBLE versions prior to 1.10.0
Description A reachable assertion issue exists in the ATT parser. A specially crafted ATT Read Multiple Variable Response (BLE ATT OP READ MULT VAR RSP) can trigger an assert, provided the Device Under Test (DUT) first sends an ATT Read Multiple Variable Request.
Recommendations Upgrade to version 1.10.0.

Exploit

Fix

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45815

Affected Products

Apache Nimble