{"schema_version": "1.6.1", "id": "CVE-2026-45816", "summary": "NULL pointer dereference vulnerability in SMP LTK request", "details": "NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event.\n\nThis requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low.\n\nThis issue affects Apache NimBLE: through 1.9.0.\n\nUsers are recommended to upgrade to version 1.10.0, which fixes the issue.", "affected": [{"ranges": [{"type": "SEMVER", "events": [{"introduced": "0"}, {"last_affected": "0"}]}]}], "references": [{"type": "WEB", "url": "https://github.com/apache/mynewt-nimble/commit/9448c5f495eb55018121b24a9dab5305c9222ea1"}, {"type": "WEB", "url": "https://lists.apache.org/thread/psppdk5j8jnq1m4jn96tnfofspgqvzvn"}]}