Osrg

Gobgp

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.42%
  • Veröffentlicht 07.05.2026 12:16:18
  • Zuletzt bearbeitet 11.05.2026 15:22:48

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.4.0, an unauthenticated remote BGP peer can trigger a fatal panic in GoBGP by sending a specially crafted BGP UPDATE message. When the s...

Exploit
  • EPSS 0.5%
  • Veröffentlicht 07.05.2026 12:16:17
  • Zuletzt bearbeitet 07.05.2026 19:43:46

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP where a malformed BGP UPDATE message can trigger a runtime err...

Exploit
  • EPSS 0.5%
  • Veröffentlicht 07.05.2026 12:16:17
  • Zuletzt bearbeitet 07.05.2026 19:46:05

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP due to a nil pointer dereference. When a malformed BGP UPDATE messag...

  • EPSS 0.36%
  • Veröffentlicht 04.05.2026 06:16:02
  • Zuletzt bearbeitet 06.05.2026 20:27:05

A vulnerability was found in osrg GoBGP up to 4.3.0. Affected is the function PathAttributeAigp.DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component AIGP Attribute Parser. Performing a manipulation results in buffer overflow. It is poss...

  • EPSS 0.46%
  • Veröffentlicht 04.05.2026 06:16:02
  • Zuletzt bearbeitet 06.05.2026 20:26:55

A vulnerability has been found in osrg GoBGP up to 4.3.0. This impacts the function SRv6L3ServiceAttribute.DecodeFromBytes of the file pkg/packet/bgp/prefix_sid.go of the component SRv6 L3 Service. Such manipulation of the argument data leads to deni...

  • EPSS 0.63%
  • Veröffentlicht 04.05.2026 05:45:12
  • Zuletzt bearbeitet 06.05.2026 20:27:58

A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by this issue is the function BMPPeerUpNotification.ParseBody/BMPStatisticsReport.ParseBody of the file pkg/packet/bmp/bmp.go of the component BMP Parser. The manipulation leads to ou...

  • EPSS 0.45%
  • Veröffentlicht 04.05.2026 05:30:16
  • Zuletzt bearbeitet 06.05.2026 20:27:43

A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry of the file pkg/packet/mrt/mrt.go. Executing a manipulation can lead to integer underflow. It is possible to launch the attack remo...

  • EPSS 0.34%
  • Veröffentlicht 04.05.2026 00:00:00
  • Zuletzt bearbeitet 11.05.2026 19:58:37

An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

  • EPSS 0.29%
  • Veröffentlicht 30.03.2026 16:15:12
  • Zuletzt bearbeitet 06.04.2026 15:52:36

A security vulnerability has been detected in osrg GoBGP up to 4.3.0. Affected is the function BGPHeader.DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component BGP Header Handler. The manipulation leads to improper access controls. Remote...

  • EPSS 0.41%
  • Veröffentlicht 30.03.2026 15:15:14
  • Zuletzt bearbeitet 06.04.2026 15:46:13

A weakness has been identified in osrg GoBGP up to 4.3.0. This impacts the function DecodeFromBytes of the file pkg/packet/bgp/bgp.go. Executing a manipulation of the argument data[1] can lead to off-by-one. The attack may be launched remotely. Attac...