CVE-2026-23750Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Golioth Pouch version 0.1.0, prior to commit 1b2219a1, contains a heap-based buffer overflow in BLE GATT server certificate handling. server_cert_write() allocates a heap buffer of size CONFIG_POUCH_SERVER_CERT_MAX_LEN when receiving the first fragment, then appends subsequent fragments using memcpy() without verifying that sufficient capacity remains. An adjacent BLE client can send unauthenticated fragments whose combined size exceeds the allocated buffer, causing a heap overflow and crash; integrity impact is also possible due to memory corruption.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 4 mentions (2026-02-26); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-02-26: 4Mentions · 2026-03-03: 1Patch / Workaround · 2026-02-26: 2Technical Details · 2026-02-26: 4Technical Details · 2026-03-03: 102-2603-03
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-264
Disclosure2Patch2
2026-03-031
Disclosure1
Full discourse5 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-23750 (CVSS:7.2, HIGH) is Awaiting Analysis. Golioth Pouch version 0.1.0, prior to commit 1b2219a1, contains a heap-based buffer overflow in BLE GATT server certific..https://nvd.nist.gov/vuln/detail/CVE-2026-23750 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-23750 is a heap‑based buffer overflow in Golioth Pouch’s BLE GATT server, rated CVSS 7.2, and is currently awaiting analysis.

    0000028
    173 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-23750 Heap-Based Buffer Overflow in Golioth Pouch 0.1.0 BLE GATT Server Certificate Handling https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23750

    Post summary

    A heap-based buffer overflow vulnerability (CVE-2026-23750) was disclosed in Golioth Pouch 0.1.0's BLE GATT server certificate handling, with no PoC, exploit, or patch details provided.

    0000049
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23750 Golioth Pouch version 0.1.0 prior to [INSERT FIXED VERSION], fixed in commit 1b2219a1, contain a heap-based buffer overflow in BLE GATT server certificate handling. s… https://www.cve.org/CVERecord?id=CVE-2026-23750

    Post summary

    CVE-2026-23750 is a heap‑based buffer overflow in Golioth Pouch’s BLE GATT server certificate handling, fixed in commit 1b2219a1; no PoC or active exploitation is reported.

    0000083
    56.6K followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-23750** pertains to a heap-based buffer overflow vulnerability in **Golioth Pouch version 0.1.0** prior to a specific fixed version. The flaw exists within the handling of BLE (Bluetooth Low Energy) GATT (Generic Attribute Profile) server certificates, specifically in the `server_cert_write()` function. An attacker can exploit this vulnerability by sending maliciously crafted, unauthenticated fragments of data to the device, leading to a heap overflow, potential crashes, and memory corruption. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #DDoS #BufferOverflow https://cvetodo.com/cve/CVE-2026-23750

    Post summary

    The post discloses a heap‑based buffer overflow in Golioth Pouch 0.1.0 affecting BLE GATT server certificates, highlighting potential crashes and memory corruption, but provides no PoC, exploit, or patch information.

    0000063
    20 followersView on X
  • The Hacker Wire@TheHackerWire
    Patch

    🟠 CVE-2026-23750 - High Golioth Pouch version 0.1.0 prior to [INSERT FIXED VERSION], fixed in commit 1b2219a1, contain a heap-based buffer overflow in BLE GATT server certificate handling. server_cert_write() allo... https://www.thehackerwire.com/vulnerability/CVE-2026-23750/ https://t.co/Zm9M0yPP1B

    Post summary

    CVE-2026-23750 is a heap-based buffer overflow in Golioth Pouch's BLE GATT server certificate handling, fixed in commit 1b2219a1; a patch is available.

    0000024
    115 followersView on X

Explore more