CVE-2026-42285
- EPSS 0.42%
- Veröffentlicht 07.05.2026 12:16:18
- Zuletzt bearbeitet 11.05.2026 15:22:48
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.4.0, an unauthenticated remote BGP peer can trigger a fatal panic in GoBGP by sending a specially crafted BGP UPDATE message. When the s...
CVE-2026-41643
- EPSS 0.5%
- Veröffentlicht 07.05.2026 12:16:17
- Zuletzt bearbeitet 07.05.2026 19:43:46
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP where a malformed BGP UPDATE message can trigger a runtime err...
CVE-2026-41642
- EPSS 0.5%
- Veröffentlicht 07.05.2026 12:16:17
- Zuletzt bearbeitet 07.05.2026 19:46:05
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP due to a nil pointer dereference. When a malformed BGP UPDATE messag...
CVE-2026-7735
- EPSS 0.36%
- Veröffentlicht 04.05.2026 06:16:02
- Zuletzt bearbeitet 06.05.2026 20:27:05
A vulnerability was found in osrg GoBGP up to 4.3.0. Affected is the function PathAttributeAigp.DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component AIGP Attribute Parser. Performing a manipulation results in buffer overflow. It is poss...
CVE-2026-7734
- EPSS 0.46%
- Veröffentlicht 04.05.2026 06:16:02
- Zuletzt bearbeitet 06.05.2026 20:26:55
A vulnerability has been found in osrg GoBGP up to 4.3.0. This impacts the function SRv6L3ServiceAttribute.DecodeFromBytes of the file pkg/packet/bgp/prefix_sid.go of the component SRv6 L3 Service. Such manipulation of the argument data leads to deni...
CVE-2026-7737
- EPSS 0.63%
- Veröffentlicht 04.05.2026 05:45:12
- Zuletzt bearbeitet 06.05.2026 20:27:58
A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by this issue is the function BMPPeerUpNotification.ParseBody/BMPStatisticsReport.ParseBody of the file pkg/packet/bmp/bmp.go of the component BMP Parser. The manipulation leads to ou...
CVE-2026-7736
- EPSS 0.45%
- Veröffentlicht 04.05.2026 05:30:16
- Zuletzt bearbeitet 06.05.2026 20:27:43
A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry of the file pkg/packet/mrt/mrt.go. Executing a manipulation can lead to integer underflow. It is possible to launch the attack remo...
CVE-2026-37461
- EPSS 0.34%
- Veröffentlicht 04.05.2026 00:00:00
- Zuletzt bearbeitet 11.05.2026 19:58:37
An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
CVE-2026-5124
- EPSS 0.29%
- Veröffentlicht 30.03.2026 16:15:12
- Zuletzt bearbeitet 06.04.2026 15:52:36
A security vulnerability has been detected in osrg GoBGP up to 4.3.0. Affected is the function BGPHeader.DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component BGP Header Handler. The manipulation leads to improper access controls. Remote...
CVE-2026-5123
- EPSS 0.41%
- Veröffentlicht 30.03.2026 15:15:14
- Zuletzt bearbeitet 06.04.2026 15:46:13
A weakness has been identified in osrg GoBGP up to 4.3.0. This impacts the function DecodeFromBytes of the file pkg/packet/bgp/bgp.go. Executing a manipulation of the argument data[1] can lead to off-by-one. The attack may be launched remotely. Attac...