CVE-2026-45815: Apache NimBLE: Remote reachable assertion in ATT Read Multiple Variable Response handler
Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLEATTOPREADMULTVARRSP) may trigger assert in ATT parser.
Severity is medium as this requires DUT to first send ATT Read Multiple Variable Request.
This issue affects Apache NimBLE: through 1.9.0.
Users are recommended to upgrade to version 1.10.0, which fixes the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45815?
CVE-2026-45815 has a severity rating of high with a CVSS score of 7.5.
How does CVE-2026-45815 affect Apache NimBLE?
CVE-2026-45815 affects Apache NimBLE by exposing a reachable assertion vulnerability in the ATT Read Multiple Variable Response handler.
What causes the vulnerability in CVE-2026-45815?
The vulnerability in CVE-2026-45815 is triggered by a specially crafted ATT Read Multiple Variable Response that may cause an assertion failure in the ATT parser.
Can CVE-2026-45815 be exploited remotely?
Yes, CVE-2026-45815 can potentially be exploited remotely if the attacker can send an ATT Read Multiple Variable Request.
What is the fix for CVE-2026-45815?
To address CVE-2026-45815, users should update to the latest version of Apache NimBLE that contains the necessary patches.