Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser.
Severity is medium as this requires DUT to first send ATT Read Multiple Variable Request.
This issue affects Apache NimBLE: through 1.9.0.
Users are recommended to upgrade to version 1.10.0, which fixes the issue.
{
"cna_assigner": "apache",
"cwe_ids": [
"CWE-617"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45815.json"
}{
"cpe": "cpe:2.3:a:apache:nimble:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.10.0"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45815.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"139478207177082567185941882417418768911",
"95906856854745850031954758292498858625",
"48009249997045134412933561375538292130",
"98946369476715814358194714597147153095",
"44963538145403444910999399215622085787",
"321006026477379003122323497770668412074",
"43190737599707061582726143531226932299",
"275920934793903790118744926010428898769",
"122008934653670842520751568050064747795",
"145776201511580565462841533239433031498",
"254153068920403215772471764778709798277",
"176127669364510892669869935237034464716",
"130226887549159589754433561844381474754",
"203539364347629758300815373225707442641",
"322200741264110633444198186349547462329",
"2593934769640683438763217653058304155",
"80618119757294527224332824764903448354",
"95401829321823866451465532883833104160",
"319148929693999394266655325344901906708",
"307044218007445019587263077978432583596",
"218609754259478236616162253113620132222",
"207851092748909014998233964443983505083",
"335465282998490024839787217935591234962",
"45358018111357770276454831224141901214",
"239540065658117949639312374512669751589",
"184747236048983471352675641958925774615",
"309820581738997359353578351761580435384",
"244116116736333796563810696767191560694",
"288268133538146007361463397286674176503",
"113395521887514319596541632687575201702",
"197661188294860262835626926268507291473",
"267868390585593816517915983992887850017"
],
"threshold": 0.9
},
"id": "CVE-2026-45815-4b83fb7f",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/apache/mynewt-nimble/commit/fae6a4874309ba0175d2c444e20f8a6bde007425",
"target": {
"file": "nimble/host/src/ble_gattc.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "111834937164864534758340404689555505836",
"length": 1218
},
"id": "CVE-2026-45815-7b71a48b",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/apache/mynewt-nimble/commit/fae6a4874309ba0175d2c444e20f8a6bde007425",
"target": {
"file": "nimble/host/src/ble_gattc.c",
"function": "ble_gattc_read_mult_cb_var"
}
}
]
"2026-08-12T16:09:37Z"