📦 Nimble

by Apache

🔍 What is Nimble?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-52435

HIGH CVSS 7.5 Jan 10, 2026

This vulnerability in Apache NimBLE allows an attacker to downgrade encrypted Bluetooth Low Energy connections to unencrypted state after a Pause Encryption procedure, enabling eavesdropping on subseq...

CVE-2025-53477

HIGH CVSS 7.5 Jan 10, 2026

A NULL pointer dereference vulnerability in Apache NimBLE's Bluetooth stack occurs when HCI connection completion or command transmission buffers lack proper validation. This could cause crashes or in...

CVE-2025-62235

HIGH CVSS 8.1 Jan 10, 2026

This vulnerability allows attackers to bypass authentication in Apache NimBLE by sending specially crafted Security Request packets. An attacker can remove existing secure bonds and force re-bonding w...

CVE-2024-51569

HIGH CVSS 7.5 Nov 26, 2024

This CVE describes an out-of-bounds read vulnerability in Apache NimBLE's Bluetooth stack. It allows reading beyond allocated memory boundaries when processing HCI events from a malicious or faulty Bl...

CVE-2024-47249

MEDIUM CVSS 5.0 Nov 26, 2024

Apache NimBLE versions through 1.7.0 have an improper array index validation vulnerability in HCI event handling that could allow memory corruption and crashes. This requires a malicious or malfunctio...

CVE-2025-53470

LOW CVSS 3.1 Jan 10, 2026

An out-of-bounds read vulnerability in Apache NimBLE's HCI H4 driver allows a malicious or malfunctioning Bluetooth controller to trigger invalid memory reads. This affects all Apache NimBLE versions ...