NULL Pointer Dereference Vulnerability in Apache NimBLE Affected by Misbehaving Controller
CVE-2026-45816

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
24 July 2026

What is CVE-2026-45816?

A NULL Pointer Dereference vulnerability exists in the Apache NimBLE stack, specifically during the LE Long Term Key Request event. This issue occurs only when asserts are disabled and in scenarios with misbehaving controllers, making it a specific and rare occurrence. Users are strongly encouraged to upgrade to version 1.10.0 or later to mitigate this risk.

Affected Version(s)

Apache NimBLE 0 <= 1.9.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chongqing Lei <leicq@seu.edu.cn>
.