CVE-2025-52435

J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE. Improper handling of Pause Encryption procedure on Link Layer results in a previously encrypted connection being left in un-encrypted state allowing an eavesdropper to observe the remainder of the exchange. This issue affects Apache NimBLE: through <= 1.8.0. Users are recommended to upgrade to version 1.9.0, which fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:nimble:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-10 10:15

Updated : 2026-01-14 16:30


NVD link : CVE-2025-52435

Mitre link : CVE-2025-52435

CVE.ORG link : CVE-2025-52435


JSON object : View

Products Affected

apache

  • nimble
CWE
CWE-5

J2EE Misconfiguration: Data Transmission Without Encryption