Apache nimble
This hub aggregates every CVE we track for Apache nimble, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
11
CVEs tracked
0
Critical
6
High
0
In CISA KEV
Severity distribution
HIGH6MEDIUM5
Monthly trend
0
0
0
4
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
6
2024-082026-07
Latest CVEs
The 11 most recently published vulnerabilities affecting Apache nimble.
- CVE-2026-46452Apache NimBLE: Mesh Proxy SAR reassembly unbounded append and unchecked failure5.3
- CVE-2026-45816Apache NimBLE: NULL pointer dereference vulnerability in SMP LTK request7.5
- CVE-2026-45815Apache NimBLE: Remote reachable assertion in ATT Read Multiple Variable Response handler7.5
- CVE-2026-45813Apache NimBLE: Incorrect data validation in BASS add/modify source operation8.8
- CVE-2026-45812Apache NimBLE: OOB Read via sizeof(pointer) in Legacy Advertising Report Handler6.5
- CVE-2026-45811Apache NimBLE: Buffer overflow in socket HCI transport7.5
- CVE-2024-51569Apache NimBLE: Lack of input sanitization leading to out-of-bound reads in Number of Completed Packets HCI event handler7.5
- CVE-2024-47250Apache NimBLE: Lack of input validation in HCI advertising report could lead to potential out-of-bound access5.0
- CVE-2024-47249Apache NimBLE: Lack of input sanitization leading to out-of-bound reads in multiple advertisement handler5.0
- CVE-2024-47248Apache NimBLE: Buffer overflow in NimBLE MESH Bluetooth stack6.3
- CVE-2024-24746Apache NimBLE: Denial of service in NimBLE Bluetooth stack7.5
Product normalization is registry-driven with AI assist and human review. How it works