CVE-2026-45815

Source
https://cve.org/CVERecord?id=CVE-2026-45815
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45815.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45815
Published
2026-07-24T12:10:38Z
Modified
2026-08-12T16:09:37Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Apache NimBLE: Remote reachable assertion in ATT Read Multiple Variable Response handler
Details

Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser.

Severity is medium as this requires DUT to first send ATT Read Multiple Variable Request.

This issue affects Apache NimBLE: through 1.9.0.

Users are recommended to upgrade to version 1.10.0, which fixes the issue.

Database specific
{
    "cna_assigner":  "apache",
    "cwe_ids":  [
        "CWE-617"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45815.json"
}
References

Affected packages

Git / github.com/apache/mynewt-nimble

Affected ranges

Type
GIT
Repo
https://github.com/apache/mynewt-nimble
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:apache:nimble:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "1.10.0"
        }
    ],
    "source":  [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

Other
nimble_1_5_0_rc1_tag
nimble_1_5_0_tag
nimble_1_6_0_rc1_tag
nimble_1_6_0_tag
nimble_1_7_0_rc1_tag
nimble_1_7_0_tag
nimble_1_8_0_rc1_tag
nimble_1_8_0_tag
nimble_1_9_0_rc1_tag
nimble_1_9_0_tag

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45815.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "139478207177082567185941882417418768911",
                "95906856854745850031954758292498858625",
                "48009249997045134412933561375538292130",
                "98946369476715814358194714597147153095",
                "44963538145403444910999399215622085787",
                "321006026477379003122323497770668412074",
                "43190737599707061582726143531226932299",
                "275920934793903790118744926010428898769",
                "122008934653670842520751568050064747795",
                "145776201511580565462841533239433031498",
                "254153068920403215772471764778709798277",
                "176127669364510892669869935237034464716",
                "130226887549159589754433561844381474754",
                "203539364347629758300815373225707442641",
                "322200741264110633444198186349547462329",
                "2593934769640683438763217653058304155",
                "80618119757294527224332824764903448354",
                "95401829321823866451465532883833104160",
                "319148929693999394266655325344901906708",
                "307044218007445019587263077978432583596",
                "218609754259478236616162253113620132222",
                "207851092748909014998233964443983505083",
                "335465282998490024839787217935591234962",
                "45358018111357770276454831224141901214",
                "239540065658117949639312374512669751589",
                "184747236048983471352675641958925774615",
                "309820581738997359353578351761580435384",
                "244116116736333796563810696767191560694",
                "288268133538146007361463397286674176503",
                "113395521887514319596541632687575201702",
                "197661188294860262835626926268507291473",
                "267868390585593816517915983992887850017"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-45815-4b83fb7f",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/apache/mynewt-nimble/commit/fae6a4874309ba0175d2c444e20f8a6bde007425",
        "target":  {
            "file":  "nimble/host/src/ble_gattc.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "111834937164864534758340404689555505836",
            "length":  1218
        },
        "id":  "CVE-2026-45815-7b71a48b",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/apache/mynewt-nimble/commit/fae6a4874309ba0175d2c444e20f8a6bde007425",
        "target":  {
            "file":  "nimble/host/src/ble_gattc.c",
            "function":  "ble_gattc_read_mult_cb_var"
        }
    }
]
vanir_signatures_modified
"2026-08-12T16:09:37Z"