CVE-2026-97152

Source
https://cve.org/CVERecord?id=CVE-2026-97152
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97152.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-97152
Downstream
Published
2026-09-24T03:17:23Z
Modified
2026-09-24T14:06:14Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:H/SA:H CVSS Calculator
Summary
[none]
Details

Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf.

Database specific
{
    "cna_assigner":  "mitre",
    "cwe_ids":  [
        "CWE-122"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97152.json"
}
References

Affected packages

Git / github.com/nanomsg/nanomsg

Affected ranges

Type
GIT
Repo
https://github.com/nanomsg/nanomsg
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0.5.0"
        },
        {
            "fixed":  "1.2.3"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

0.*
0.1-alpha
0.2-alpha
0.3-beta
0.4-beta
0.5-beta
0.6-beta
0.7-beta
0.8-beta
0.9-beta
1.*
1.0.0
1.0.0-rc1
1.0.0-rc2
1.1.0
1.1.0-rc1
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2
1.2.1
1.2.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97152.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "287009897241120144265531165140395810049",
                "274430065088616682288390194085542061785",
                "46147651555268843306278932351840002642",
                "311153397563635737156656258054851071624",
                "87668588403922739184672162694556759276"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-97152-0a1b42aa",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/nanomsg/nanomsg/commit/6dac4ea9bd0f8cd215925aefd7fdcc62714f67d7",
        "target":  {
            "file":  "src/utils/closefd.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "322197853003812991144294540737187127422",
            "length":  120
        },
        "id":  "CVE-2026-97152-c9f945b3",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/nanomsg/nanomsg/commit/6dac4ea9bd0f8cd215925aefd7fdcc62714f67d7",
        "target":  {
            "file":  "src/utils/closefd.c",
            "function":  "nn_closefd"
        }
    }
]
vanir_signatures_modified
"2026-09-24T14:06:14Z"