{"id":"CVE-2026-97152","published":"2026-09-24T04:18:06.213","lastModified":"2026-09-24T21:04:40.340","description":"Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-122"],"vendors":[],"products":[],"references":[{"url":"https://github.com/nanomsg/nanomsg/pull/1130","tags":[]},{"url":"https://github.com/nanomsg/nanomsg/releases/tag/1.2.3","tags":[]},{"url":"https://nanomsg.org","tags":[]}],"exploitRefs":[{"url":"https://github.com/nanomsg/nanomsg/pull/1130","tags":[]},{"url":"https://github.com/nanomsg/nanomsg/releases/tag/1.2.3","tags":[]}],"hasPoc":true,"ai":null}