CVE-2025-52435

CVE-2025-52435: Apache Mynewt NimBLE: Invalid error handling in pause encryption procedure in NimBLE controller

Vendor Apache Software Foundation
Product Apache Mynewt NimBLE
Published January 10, 2026
Last update January 12, 2026

CVSS base score

What the vulnerability does

Description

J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE. Improper handling of Pause Encryption procedure on Link Layer results in a previously encrypted connection being left in un-encrypted state allowing an eavesdropper to observe the remainder of the exchange. This issue affects Apache NimBLE: through <= 1.8.0. Users are recommended to upgrade to version 1.9.0, which fixes the issue.

Key dates

Disclosure timeline

January 10, 2026 CVE published
January 12, 2026 Record updated