Buffer Overflow Vulnerability in Nanomsg WebSocket Transport
CVE-2026-97152

8.6HIGH

Key Information:

Vendor

Nanomsg

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-97152?

A significant buffer overflow vulnerability exists in the WebSocket transport of Nanomsg versions 0.5-beta through 1.x prior to 1.2.3. This security flaw arises from an unchecked copy of the Sec-WebSocket-Version header when using the snprintf function, allowing remote attackers to exploit the flaw. Successful exploitation could lead to unauthorized access or service disruption. Users are advised to upgrade to version 1.2.3 or later to mitigate the risk.

Affected Version(s)

Nanomsg 0.5.0 < 1.2.3

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.