Description
Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf.
Published: 2026-09-24
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Upgrade to nanomsg 1.2.3 or higher, or use NNG which is hardened for hostile networks.


Vendor Workaround

Disable the websocket transport, or ensure that it is only available to trusted peers.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Nanomsg
Nanomsg nanomsg
Vendors & Products Nanomsg
Nanomsg nanomsg

Thu, 24 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Title Remote Buffer Overflow in Nanomsg WebSocket Transport

Thu, 24 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Description Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf.
Weaknesses CWE-122
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-24T03:17:23.503Z

Reserved: 2026-09-24T03:17:23.134Z

Link: CVE-2026-97152

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-24T04:18:06.213

Modified: 2026-09-24T04:18:06.213

Link: CVE-2026-97152

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T09:08:49Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow