Back to overview

CVE-2026-45816

HIGH
7.5
CVSS 3.1
Description
NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.

Metadata

CVE ID
CVE-2026-45816
State
PUBLISHED
Assigner
apache
Reserved
2026-05-13 09:41 UTC
Published
2026-07-24 12:11 UTC
Last updated
2026-07-24 18:22 UTC
Primary CWE
CWE-476
CWE-476 NULL Pointer Dereference
Vendor / Product
Apache Software Foundation / Apache NimBLE
Sources
cve.org  ·  NVD

Severity & Metrics

7.5 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Apache Software Foundation Apache NimBLE 0 ≤ 1.9.0
Weakness (CWE)
CWESourceDescription
CWE-476 cna CWE-476 NULL Pointer Dereference
CVSS scores (1)
ScoreSeverityVersionSourceVector
7.5 HIGH 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Back to overview