Input validation error in Apache NimBLE - CVE-2026-46452

 

Input validation error in Apache NimBLE - CVE-2026-46452

Published: August 24, 2026


Vulnerability identifier: #VU144753
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-46452
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in mesh proxy SAR reassembly when processing crafted mesh proxy SAR data. A remote attacker can send malformed reassembly input to cause a denial of service.

The issue could result in broken data being passed toward the application, leading to memory pressure and unstable parsing behavior.


Affected software

Apache NimBLE

How to mitigate CVE-2026-46452

Install security update from vendor's website.

Apache NimBLE - update to 1.10.0

External References

Related Security Bulletins