Back to overview

CVE-2026-45813

HIGH
8.8
CVSS 3.1
Description
Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper validation when parsing BASS service  "Add Source" and "Modify Source" operation PDU could results in stack buffer overflow or arbitrary out-of-bound read. This can be triggered by nearby devices over Bluetooth connection, however pairing is required prior to accessing BASS service, which depending on device configuration may or may not require user action. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.

Metadata

CVE ID
CVE-2026-45813
State
PUBLISHED
Assigner
apache
Reserved
2026-05-13 09:02 UTC
Published
2026-07-24 12:10 UTC
Last updated
2026-07-24 18:18 UTC
Primary CWE
CWE-787
CWE-787 Out-of-bounds Write
Vendor / Product
Apache Software Foundation / Apache NimBLE
Sources
cve.org  ·  NVD

Severity & Metrics

8.8 HIGH CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Apache Software Foundation Apache NimBLE 0 ≤ 1.9.0
Weakness (CWE)
CWESourceDescription
CWE-191 cna CWE-191 Integer Underflow (Wrap or Wraparound)
CWE-787 cna CWE-787 Out-of-bounds Write
CVSS scores (1)
ScoreSeverityVersionSourceVector
8.8 HIGH 3.1 adp CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview