{"schema_version":1,"title":"Apache Software Foundation NimBLE vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 6 vulnerabilities in Apache Software Foundation NimBLE: 0 in the last 7 days and 6 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-46452, was published on 24 July 2026.","url":"https://junglewise.ai/threats/technologies/nimble","json_url":"https://junglewise.ai/threats/technologies/nimble.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/nimble","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":6,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":6,"last_365_days":6},"latest":[{"cve":"CVE-2026-46452","cvss":0,"slug":"cve-2026-46452-apache-nimble-improper-input-validation-in-mesh-proxy-sar","title":"Apache NimBLE Improper Input Validation in Mesh Proxy SAR reassembly","severity":"info","exploited":false,"published_at":"2026-07-24T13:18:25.097+00:00","url":"https://junglewise.ai/threats/cve-2026-46452-apache-nimble-improper-input-validation-in-mesh-proxy-sar"},{"cve":"CVE-2026-45816","cvss":2.1,"slug":"cve-2026-45816-apache-nimble-null-pointer-dereference-in-le-long-term-key","title":"Apache NimBLE NULL pointer dereference in LE Long Term Key Request","severity":"info","exploited":false,"published_at":"2026-07-24T13:18:24.307+00:00","url":"https://junglewise.ai/threats/cve-2026-45816-apache-nimble-null-pointer-dereference-in-le-long-term-key"},{"cve":"CVE-2026-45815","cvss":4.3,"slug":"cve-2026-45815-apache-nimble-reachable-assertion-in-att-parser","title":"Apache NimBLE reachable assertion in ATT parser","severity":"info","exploited":false,"published_at":"2026-07-24T13:18:24.2+00:00","url":"https://junglewise.ai/threats/cve-2026-45815-apache-nimble-reachable-assertion-in-att-parser"},{"cve":"CVE-2026-45813","cvss":0,"slug":"cve-2026-45813-apache-nimble-stack-overflow-in-bass-service","title":"Apache NimBLE stack overflow in BASS service","severity":"info","exploited":false,"published_at":"2026-07-24T13:18:24.087+00:00","url":"https://junglewise.ai/threats/cve-2026-45813-apache-nimble-stack-overflow-in-bass-service"},{"cve":"CVE-2026-45812","cvss":3.5,"slug":"cve-2026-45812-apache-nimble-incorrect-buffer-size-calculation-in-hci-event","title":"Apache NimBLE incorrect buffer size calculation in HCI event processing","severity":"info","exploited":false,"published_at":"2026-07-24T13:18:23.967+00:00","url":"https://junglewise.ai/threats/cve-2026-45812-apache-nimble-incorrect-buffer-size-calculation-in-hci-event"},{"cve":"CVE-2026-45811","cvss":3.1,"slug":"cve-2026-45811-apache-nimble-buffer-overflow-in-hci-socket-transport","title":"Apache NimBLE buffer overflow in HCI socket transport","severity":"info","exploited":false,"published_at":"2026-07-24T13:18:23.847+00:00","url":"https://junglewise.ai/threats/cve-2026-45811-apache-nimble-buffer-overflow-in-hci-socket-transport"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Apache Software Foundation IoTDB","slug":"iotdb","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/iotdb"},{"name":"Apache Software Foundation Apache CXF","slug":"cxf","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/cxf"},{"name":"Apache Software Foundation ActiveMQ All","slug":"activemq-all","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/activemq-all"},{"name":"Apache Software Foundation Answer","slug":"answer","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/answer"},{"name":"Apache Software Foundation Dolphinscheduler","slug":"dolphinscheduler","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/dolphinscheduler"},{"name":"Apache Software Foundation JSPWiki","slug":"jspwiki","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/jspwiki"},{"name":"Apache Software Foundation Apache Kvrocks","slug":"kvrocks","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/kvrocks"},{"name":"Apache Software Foundation NiFi","slug":"nifi","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/nifi"},{"name":"Apache Software Foundation Apache Wicket","slug":"wicket","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/wicket"},{"name":"Apache Software Foundation Gravitino","slug":"gravitino","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/gravitino"},{"name":"Apache Software Foundation Syncope","slug":"syncope","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/syncope"},{"name":"Apache Software Foundation Zeppelin","slug":"zeppelin","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/zeppelin"}],"technology":{"hub":true,"name":"Apache Software Foundation NimBLE","slug":"nimble","vendor":{"name":"Apache Software Foundation","slug":"apache-software-foundation","url":"https://junglewise.ai/threats/vendors/apache-software-foundation"},"aliases":[],"category":"library","homepage":"https://mynewt.apache.org/","repo_url":"https://github.com/apache/mynewt-nimble","description":"NimBLE is an open-source Bluetooth Low Energy (BLE) stack designed for resource-constrained devices.","url":"https://junglewise.ai/threats/technologies/nimble"},"most_severe":[{"cve":"CVE-2026-45815","cvss":4.3,"slug":"cve-2026-45815-apache-nimble-reachable-assertion-in-att-parser","title":"Apache NimBLE reachable assertion in ATT parser","severity":"info","exploited":false,"published_at":"2026-07-24T13:18:24.2+00:00","url":"https://junglewise.ai/threats/cve-2026-45815-apache-nimble-reachable-assertion-in-att-parser"},{"cve":"CVE-2026-45812","cvss":3.5,"slug":"cve-2026-45812-apache-nimble-incorrect-buffer-size-calculation-in-hci-event","title":"Apache NimBLE incorrect buffer size calculation in HCI event processing","severity":"info","exploited":false,"published_at":"2026-07-24T13:18:23.967+00:00","url":"https://junglewise.ai/threats/cve-2026-45812-apache-nimble-incorrect-buffer-size-calculation-in-hci-event"},{"cve":"CVE-2026-45811","cvss":3.1,"slug":"cve-2026-45811-apache-nimble-buffer-overflow-in-hci-socket-transport","title":"Apache NimBLE buffer overflow in HCI socket transport","severity":"info","exploited":false,"published_at":"2026-07-24T13:18:23.847+00:00","url":"https://junglewise.ai/threats/cve-2026-45811-apache-nimble-buffer-overflow-in-hci-socket-transport"},{"cve":"CVE-2026-45816","cvss":2.1,"slug":"cve-2026-45816-apache-nimble-null-pointer-dereference-in-le-long-term-key","title":"Apache NimBLE NULL pointer dereference in LE Long Term Key Request","severity":"info","exploited":false,"published_at":"2026-07-24T13:18:24.307+00:00","url":"https://junglewise.ai/threats/cve-2026-45816-apache-nimble-null-pointer-dereference-in-le-long-term-key"},{"cve":"CVE-2026-46452","cvss":0,"slug":"cve-2026-46452-apache-nimble-improper-input-validation-in-mesh-proxy-sar","title":"Apache NimBLE Improper Input Validation in Mesh Proxy SAR reassembly","severity":"info","exploited":false,"published_at":"2026-07-24T13:18:25.097+00:00","url":"https://junglewise.ai/threats/cve-2026-46452-apache-nimble-improper-input-validation-in-mesh-proxy-sar"},{"cve":"CVE-2026-45813","cvss":0,"slug":"cve-2026-45813-apache-nimble-stack-overflow-in-bass-service","title":"Apache NimBLE stack overflow in BASS service","severity":"info","exploited":false,"published_at":"2026-07-24T13:18:24.087+00:00","url":"https://junglewise.ai/threats/cve-2026-45813-apache-nimble-stack-overflow-in-bass-service"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}