Reachable Assertion Vulnerability in Apache NimBLE Affected by Specially Crafted ATT Requests
CVE-2026-45815

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
24 July 2026

What is CVE-2026-45815?

This vulnerability in Apache NimBLE arises from a flaw in the ATT (Attribute Protocol) parser, specifically triggered by a specially crafted ATT Read Multiple Variable Response. If exploited, this vulnerability may cause the parser to assert, leading to potential disruption in services. The issue requires a prior ATT Read Multiple Variable Request from a Device Under Test (DUT), making it a targeted attack vector. To ensure system integrity and security, users are strongly urged to upgrade to version 1.10.0 of Apache NimBLE, which includes a patch to mitigate this vulnerability effectively.

Affected Version(s)

Apache NimBLE 0 <= 1.9.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Amemoyoi https://github.com/Amemoyoi
.