Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Upgrade to nanomsg 1.2.3 or higher, or use NNG which is hardened for hostile networks.


Workaround

Disable the websocket transport, or ensure that it is only available to trusted peers.

History

Thu, 24 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Title Remote Buffer Overflow in Nanomsg WebSocket Transport

Thu, 24 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Description Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf.
Weaknesses CWE-122
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:H/SA:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-24T03:17:23.503Z

Reserved: 2026-09-24T03:17:23.134Z

Link: CVE-2026-97152

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-24T04:18:06.213

Modified: 2026-09-24T04:18:06.213

Link: CVE-2026-97152

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T04:30:14Z

Weaknesses