Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to nanomsg 1.2.3 or higher, or use NNG which is hardened for hostile networks.
Vendor Workaround
Disable the websocket transport, or ensure that it is only available to trusted peers.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 24 Sep 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nanomsg
Nanomsg nanomsg |
|
| Vendors & Products |
Nanomsg
Nanomsg nanomsg |
Thu, 24 Sep 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Buffer Overflow in Nanomsg WebSocket Transport |
Thu, 24 Sep 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf. | |
| Weaknesses | CWE-122 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-24T03:17:23.503Z
Reserved: 2026-09-24T03:17:23.134Z
Link: CVE-2026-97152
No data.
Status : Received
Published: 2026-09-24T04:18:06.213
Modified: 2026-09-24T04:18:06.213
Link: CVE-2026-97152
No data.
OpenCVE Enrichment
Updated: 2026-09-24T09:08:49Z
-
CWE-122
Heap-based Buffer Overflow