{"id":"CVE-2026-97152","title":"Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf.","summary":"Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf.","severity":"high","cvss":8.6,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:H/SA:H","cwe":["CWE-122"],"vendor":"Nanomsg","product":"Nanomsg","affected":["Nanomsg >= 0.5.0 < 1.2.3"],"published":"2026-09-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T04:18:06.213","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-97152","references":[{"url":"https://github.com/nanomsg/nanomsg/pull/1130","label":"cve@mitre.org"},{"url":"https://github.com/nanomsg/nanomsg/releases/tag/1.2.3","label":"cve@mitre.org"},{"url":"https://nanomsg.org","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-09-24T03:37:24.188Z","slug":"CVE-2026-97152","body":"## Overview\n\nNanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":47.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}