LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-45816

apache · nimble

Published
CVSS7.5
Severityhigh
WeaknessCWE-476
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-45816

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-45816.