CVE-2026-97152

Summary

Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf.

Affected Software

VendorProductVersion RangeStatus
NanomsgNanomsg0.5.0 < 1.2.3affected

Weaknesses

  • CWE-122: CWE-122 Heap-based Buffer Overflow

Workarounds

Disable the websocket transport, or ensure that it is only available to trusted peers.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References