PatchSiren cyber security CVE debrief
CVE-2026-45816 Apache CVE debrief
CVE-2026-45816 is a NULL Pointer Dereference vulnerability in Apache NimBLE, specifically in the LE Long Term Key Request event. The vulnerability requires disabled asserts, which otherwise would trigger before the NULL dereference, and a bogus or misbehaving controller. Due to these conditions, the severity of the issue is considered low. The vulnerability affects Apache NimBLE through version 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.
- Vendor
- Apache
- Product
- Nimble
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-24
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-24
- Advisory updated
- 2026-07-27
Who should care
Users of Apache NimBLE, especially those who have not upgraded to version 1.10.0, should be aware of this vulnerability. The issue, although having a high CVSS score of 7.5, presents a low severity due to the specific conditions required for exploitation.
Technical summary
The CVE-2026-45816 vulnerability is a NULL Pointer Dereference issue within Apache NimBLE's handling of LE Long Term Key Request events. For the vulnerability to be exploitable, asserts must be disabled, and the controller must be bogus or misbehave. This specific set of conditions leads to a low severity assessment despite the CVSS score of 7.5. The affected versions of Apache NimBLE are up to 1.9.0, and the issue is resolved in version 1.10.0.
Defensive priority
Given the low severity but high CVSS score of CVE-2026-45816, defensive priority should be focused on upgrading to version 1.10.0 of Apache NimBLE if currently using a version up to 1.9.0. Additionally, monitoring for any unusual controller behavior and ensuring that asserts are enabled can help mitigate potential risks.
Recommended defensive actions
- Upgrade to Apache NimBLE version 1.10.0 or later
- Monitor controller behavior for potential misbehavior
- Ensure asserts are enabled in production environments
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-07-24T13:18:24.307Z and was last modified on 2026-07-27T14:40:54.387Z. The NVD entry is currently Analyzed. Evidence is limited to public sources and may not reflect the full scope or details of the vulnerability. Defenders should verify the affected versions of Apache NimBLE and review the official advisory for specific guidance. The CVE-2026-45816 vulnerability requires additional review for potential exposure, especially in environments with disabled asserts or misbehaving controllers.
Official resources
-
CVE-2026-45816 CVE record
CVE.org
-
CVE-2026-45816 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Patch
-
Mitigation or vendor reference
[email protected] - Mailing List, Vendor Advisory
-
Mitigation or vendor reference
af854a3a-2127-422b-91ae-364da2661108 - Mailing List, Third Party Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-24T13:18:24.307Z and has not been modified since then. The NVD entry is currently Analyzed.