{"schema_version": "1.6.1", "id": "CVE-2026-45815", "summary": "Remote reachable assertion in ATT Read Multiple Variable Response handler", "details": "Reachable Assertion vulnerability in Apache NimBLE.\nA specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser.\n\nSeverity is medium as this requires DUT to first send ATT Read Multiple Variable Request.\n\nThis issue affects Apache NimBLE: through 1.9.0.\n\nUsers are recommended to upgrade to version 1.10.0, which fixes the issue.", "affected": [{"ranges": [{"type": "SEMVER", "events": [{"introduced": "0"}, {"last_affected": "0"}]}]}], "references": [{"type": "WEB", "url": "https://github.com/apache/mynewt-nimble/commit/fae6a4874309ba0175d2c444e20f8a6bde007425"}, {"type": "WEB", "url": "https://lists.apache.org/thread/3d09hgo5zmm7dnryst3tb9857hk1bbos"}]}