Back

HIGH

Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf

Published Sep 24, 2026

Description

Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf.

Affected products

Remediation

Vendor solution

Upgrade to nanomsg 1.2.3 or higher, or use NNG which is hardened for hostile networks.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 24, 2026
Updated Sep 24, 2026
Reserved Sep 24, 2026
CISA Vulnrichment
Updated Sep 24, 2026
NVD
Status Received
Modified Sep 24, 2026
Red Hat
Severity n/a
Public date n/a