PT-2026-1837 · Apache · Apache Nimble

Published

2026-01-09

·

Updated

2026-01-12

·

CVE-2025-62235

CVSS v3.1

8.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache NimBLE versions through 1.8.0
Description A flaw exists in Apache NimBLE that allows authentication bypass through spoofing. Receiving a specially crafted Security Request can result in the removal of the original bond and re-bonding with an impostor.
Recommendations Upgrade to version 1.9.0.

Fix

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

CVE-2025-62235

Affected Products

Apache Nimble