Improper Input Validation Flaw in Apache NimBLE Affecting Version 1.9.0
CVE-2026-46452

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
24 July 2026

What is CVE-2026-46452?

An improper input validation vulnerability exists in Apache NimBLE, specifically in the Mesh Proxy SAR reassembly process. This flaw can cause the application to receive corrupted data, leading to memory pressure and unpredictable behavior during parsing. Users are advised to upgrade to version 1.10.0, which addresses this issue, ensuring better stability and reliability in data handling.

Affected Version(s)

Apache NimBLE 0 <= 1.9.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yicheng Yang <orangeyyc.mail@gmail.com>
.