Junglewise Threat Intelligence

CVE-2026-45815: Apache NimBLE reachable assertion in ATT parser

CVE-2026-45815 · Severity: info · CVSS 4.3 · Published 2026-07-24

Technologies: Apache Software Foundation NimBLE. Vendors: Apache Software Foundation, Apache.

Executive brief

Apache NimBLE, a Bluetooth Low Energy (BLE) stack, is vulnerable to a denial-of-service condition. An attacker within Bluetooth range can send a specially crafted response to a device's request for data, causing the software to crash or stop responding. This could disrupt the operation of smart devices or industrial sensors that rely on this library for wireless communication.

Technical details

A reachable assertion (CWE-617) exists in the Apache NimBLE ATT (Attribute Protocol) parser. The vulnerability is triggered when the Device Under Test (DUT) sends a 'BLE_ATT_OP_READ_MULT_VAR_REQ' and receives a malformed 'BLE_ATT_OP_READ_MULT_VAR_RSP' from a peer. The parser fails to correctly handle responses that do not match the expected format or number of requested values, leading to a triggered assertion and subsequent process termination. This issue is fixed in version 1.10.0 by refactoring the GATT Read Multiple Variable Char Value response handling to ignore malformed responses and report an error to the application instead of crashing.

Affected products

  • Apache NimBLE through 1.9.0

Timeline

  • 2026-07-24: advisory: NVD publication date
  • 2026-07-24: disclosed: Apache Software Foundation disclosure
  • 2026-07-24: patched: Fix committed in version 1.10.0

References

Related threats