{"id":"UBUNTU-CVE-2026-97152","details":"Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf.","modified":"2026-09-25T06:37:31.223148005Z","published":"2026-09-24T00:00:00Z","upstream":["CVE-2026-97152"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-97152"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-97152"},{"type":"REPORT","url":"https://github.com/nanomsg/nanomsg/pull/1130"},{"type":"REPORT","url":"https://github.com/nanomsg/nanomsg/releases/tag/1.2.3"},{"type":"REPORT","url":"https://nanomsg.org"}],"affected":[{"package":{"name":"nanomsg","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/nanomsg?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.5~beta+dfsg-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libnanomsg0","binary_version":"0.5~beta+dfsg-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-97152.json"}},{"package":{"name":"nanomsg","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/nanomsg?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.8~beta+dfsg-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libnanomsg4","binary_version":"0.8~beta+dfsg-1"},{"binary_name":"nanomsg-utils","binary_version":"0.8~beta+dfsg-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-97152.json"}},{"package":{"name":"nanomsg","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/nanomsg?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.1.5+dfsg-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libnanomsg5","binary_version":"1.1.5+dfsg-1"},{"binary_version":"1.1.5+dfsg-1","binary_name":"nanomsg-utils"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-97152.json"}},{"package":{"name":"nanomsg","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/nanomsg?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.1.5+dfsg-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libnanomsg5","binary_version":"1.1.5+dfsg-1"},{"binary_name":"nanomsg-utils","binary_version":"1.1.5+dfsg-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-97152.json"}},{"package":{"name":"nanomsg","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/nanomsg?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.1.5+dfsg-1.1"],"ecosystem_specific":{"binaries":[{"binary_name":"libnanomsg5","binary_version":"1.1.5+dfsg-1.1"},{"binary_version":"1.1.5+dfsg-1.1","binary_name":"nanomsg-utils"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-97152.json"}},{"package":{"name":"nanomsg","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/nanomsg?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.1.5+dfsg-1.1build2","1.1.5+dfsg-1.2"],"ecosystem_specific":{"binaries":[{"binary_name":"libnanomsg5","binary_version":"1.1.5+dfsg-1.2"},{"binary_name":"nanomsg-utils","binary_version":"1.1.5+dfsg-1.2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-97152.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:H/SA:H"},{"type":"Ubuntu","score":"medium"}]}