https://seclists.org/oss-sec/2026/q1/39: CVE-2025-52435: Apache NimBLE: Invalid error handling in pause encryption proceduin NimBLE controller
Published Jan 8, 2026
·Updated
Affected Software
1 affected component
Apache NimBLE<=1.8.0
Frequently Asked Questions
1
What is the severity of CVE-2025-52435?
The severity of CVE-2025-52435 is classified as important.
2
Which versions of Apache NimBLE are affected by CVE-2025-52435?
Apache NimBLE versions through 1.8.0 are affected by CVE-2025-52435.
3
What is the main issue described in CVE-2025-52435?
CVE-2025-52435 describes improper handling of the Pause Encryption procedure in the NimBLE controller, leading to data transmission without encryption.
4
How do I fix CVE-2025-52435?
To fix CVE-2025-52435, you should upgrade to a version of Apache NimBLE that is later than 1.8.0.
5
What are the potential consequences of CVE-2025-52435?
The potential consequences of CVE-2025-52435 include exposure of sensitive data due to unencrypted connections.