{"id":"CVE-2026-45815","summary":"Apache NimBLE: Remote reachable assertion in ATT Read Multiple Variable Response handler","details":"Reachable Assertion vulnerability in Apache NimBLE.\nA specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser.\n\nSeverity is medium as this requires DUT to first send ATT Read Multiple Variable Request.\n\nThis issue affects Apache NimBLE: through 1.9.0.\n\nUsers are recommended to upgrade to version 1.10.0, which fixes the issue.","modified":"2026-07-29T08:20:16.891454Z","published":"2026-07-24T12:10:38.456Z","database_specific":{"cwe_ids":["CWE-617"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45815.json","cna_assigner":"apache"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/07/24/14"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45815.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/3d09hgo5zmm7dnryst3tb9857hk1bbos"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45815"},{"type":"FIX","url":"https://github.com/apache/mynewt-nimble/commit/fae6a4874309ba0175d2c444e20f8a6bde007425"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/mynewt-nimble","events":[{"introduced":"0"},{"fixed":"a7a156f28954819e158b62dd613008f22f9cf73b"},{"fixed":"fae6a4874309ba0175d2c444e20f8a6bde007425"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:apache:nimble:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.10.0"}]}}],"versions":["nimble_1_9_0_tag","nimble_1_9_0_rc1_tag","nimble_1_8_0_tag","nimble_1_8_0_rc1_tag","nimble_1_7_0_tag","nimble_1_7_0_rc1_tag","nimble_1_6_0_tag","nimble_1_6_0_rc1_tag","nimble_1_5_0_tag","nimble_1_5_0_rc1_tag"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45815.json","vanir_signatures_modified":"2026-07-29T08:20:16Z","vanir_signatures":[{"digest":{"line_hashes":["139478207177082567185941882417418768911","95906856854745850031954758292498858625","48009249997045134412933561375538292130","98946369476715814358194714597147153095","44963538145403444910999399215622085787","321006026477379003122323497770668412074","43190737599707061582726143531226932299","275920934793903790118744926010428898769","122008934653670842520751568050064747795","145776201511580565462841533239433031498","254153068920403215772471764778709798277","176127669364510892669869935237034464716","130226887549159589754433561844381474754","203539364347629758300815373225707442641","322200741264110633444198186349547462329","2593934769640683438763217653058304155","80618119757294527224332824764903448354","95401829321823866451465532883833104160","319148929693999394266655325344901906708","307044218007445019587263077978432583596","218609754259478236616162253113620132222","207851092748909014998233964443983505083","335465282998490024839787217935591234962","45358018111357770276454831224141901214","239540065658117949639312374512669751589","184747236048983471352675641958925774615","309820581738997359353578351761580435384","244116116736333796563810696767191560694","288268133538146007361463397286674176503","113395521887514319596541632687575201702","197661188294860262835626926268507291473","267868390585593816517915983992887850017"],"threshold":0.9},"id":"CVE-2026-45815-4b83fb7f","signature_type":"Line","signature_version":"v1","source":"https://github.com/apache/mynewt-nimble/commit/fae6a4874309ba0175d2c444e20f8a6bde007425","target":{"file":"nimble/host/src/ble_gattc.c"},"deprecated":false},{"deprecated":false,"digest":{"length":1218,"function_hash":"111834937164864534758340404689555505836"},"id":"CVE-2026-45815-7b71a48b","signature_type":"Function","signature_version":"v1","source":"https://github.com/apache/mynewt-nimble/commit/fae6a4874309ba0175d2c444e20f8a6bde007425","target":{"file":"nimble/host/src/ble_gattc.c","function":"ble_gattc_read_mult_cb_var"}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}