Reachable Assertion Affecting apache/mynewt-nimble package, versions [,1.10.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.6% (46th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-APACHEMYNEWTNIMBLE-18306735
  • published25 Jul 2026
  • disclosed24 Jul 2026
  • creditUnknown

Introduced: 24 Jul 2026

NewCVE-2026-45815  (opens in a new tab)
CWE-617  (opens in a new tab)

How to fix?

Upgrade apache/mynewt-nimble to version 1.10.0 or higher.

Overview

Affected versions of this package are vulnerable to Reachable Assertion via the ATT Read Multiple Variable Response handler. An attacker can cause the application to terminate unexpectedly by sending a specially crafted BLE_ATT_OP_READ_MULT_VAR_RSP message after the device under test initiates an ATT Read Multiple Variable Request. This is only exploitable if the device first sends an ATT Read Multiple Variable Request.

CVSS Base Scores

version 4.0
version 3.1