CVE-2026-45816
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
24/07/2026
Last modified:
24/07/2026
Description
NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event.<br />
<br />
This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low.<br />
<br />
This issue affects Apache NimBLE: through 1.9.0.<br />
<br />
Users are recommended to upgrade to version 1.10.0, which fixes the issue.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH



