Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to nanomsg 1.2.3 or higher, or use NNG which is hardened for hostile networks.
Workaround
Disable the websocket transport, or ensure that it is only available to trusted peers.
References
History
Thu, 24 Sep 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf. | |
| Weaknesses | CWE-122 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-24T03:17:23.503Z
Reserved: 2026-09-24T03:17:23.134Z
Link: CVE-2026-97152
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses