Input validation error in Apache NimBLE - CVE-2026-46452
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in mesh proxy SAR reassembly when processing crafted mesh proxy SAR data. A remote attacker can send malformed reassembly input to cause a denial of service.
The issue could result in broken data being passed toward the application, leading to memory pressure and unstable parsing behavior.