Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLEATTOPREADMULTVARRSP) may trigger assert in ATT parser.
Severity is medium as this requires DUT to first send ATT Read Multiple Variable Request.
This issue affects Apache NimBLE: through 1.9.0.
Users are recommended to upgrade to version 1.10.0, which fixes the issue.
{
"cna_assigner": "apache",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45815.json",
"cwe_ids": [
"CWE-617"
]
}"2026-07-27T09:24:24Z"
[
{
"target": {
"file": "nimble/host/src/ble_gattc.c"
},
"id": "CVE-2026-45815-4b83fb7f",
"digest": {
"line_hashes": [
"139478207177082567185941882417418768911",
"95906856854745850031954758292498858625",
"48009249997045134412933561375538292130",
"98946369476715814358194714597147153095",
"44963538145403444910999399215622085787",
"321006026477379003122323497770668412074",
"43190737599707061582726143531226932299",
"275920934793903790118744926010428898769",
"122008934653670842520751568050064747795",
"145776201511580565462841533239433031498",
"254153068920403215772471764778709798277",
"176127669364510892669869935237034464716",
"130226887549159589754433561844381474754",
"203539364347629758300815373225707442641",
"322200741264110633444198186349547462329",
"2593934769640683438763217653058304155",
"80618119757294527224332824764903448354",
"95401829321823866451465532883833104160",
"319148929693999394266655325344901906708",
"307044218007445019587263077978432583596",
"218609754259478236616162253113620132222",
"207851092748909014998233964443983505083",
"335465282998490024839787217935591234962",
"45358018111357770276454831224141901214",
"239540065658117949639312374512669751589",
"184747236048983471352675641958925774615",
"309820581738997359353578351761580435384",
"244116116736333796563810696767191560694",
"288268133538146007361463397286674176503",
"113395521887514319596541632687575201702",
"197661188294860262835626926268507291473",
"267868390585593816517915983992887850017"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/apache/mynewt-nimble/commit/fae6a4874309ba0175d2c444e20f8a6bde007425"
},
{
"target": {
"function": "ble_gattc_read_mult_cb_var",
"file": "nimble/host/src/ble_gattc.c"
},
"id": "CVE-2026-45815-7b71a48b",
"digest": {
"function_hash": "111834937164864534758340404689555505836",
"length": 1218.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/apache/mynewt-nimble/commit/fae6a4874309ba0175d2c444e20f8a6bde007425"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45815.json"