Impact
Nanomsg versions 0.5‑beta through 1.x prior to 1.2.3 contain a buffer overflow in the WebSocket transport caused by an unchecked copy of the Sec‑WebSocket‑Version header via snprintf. An attacker who can initiate a WebSocket handshake with a specially crafted header can corrupt memory and potentially execute arbitrary code on the vulnerable system.
Affected Systems
Affected versions are Nanomsg 0.5‑beta up to just before 1.2.3, covering all releases of the Nanomsg library prior to the 1.2.3 update. The vulnerability only exists when the WebSocket transport is enabled; if the WebSocket option is disabled or limited to trusted peers, the issue does not affect those installations.
Risk and Exploitability
The CVSS base score of 8.6 indicates high severity. EPSS data is not available, so the likelihood of public exploitation remains uncertain, and the vulnerability is not yet listed in the CISA KEV catalog. Attackers would need to reach a listening service that exposes the WebSocket transport on untrusted networks, making the likely attack vector remote.
OpenCVE Enrichment