VendorsOsrggobgpall versions
Vulnerabilities

Osrg GoBGP

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2025-43973
An issue was discovered in GoBGP before 3.35.0. pkg/packet/rtr/rtr.go does not verify that the input length corresponds to a situation in which all bytes are available for an RTR message.
Published 2025-04-21 · Analyzed
9.8EPSS 0.006
CVE-2025-43971
An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen.
Published 2025-04-21 · Analyzed
8.6EPSS 0.005
CVE-2026-7737
osrg GoBGP BMP Parser bmp.go BMPStatisticsReport.ParseBody out-of-bounds
Published 2026-05-04 · Analyzed
7.5EPSS 0.009
CVE-2026-7734
osrg GoBGP SRv6 L3 Service prefix_sid.go SRv6L3ServiceAttribute.DecodeFromBytes denial of service
Published 2026-05-04 · Analyzed
7.5EPSS 0.009
CVE-2026-7736
osrg GoBGP mrt.go parseRibEntry integer underflow
Published 2026-05-04 · Analyzed
7.5EPSS 0.006
CVE-2026-7735
osrg GoBGP AIGP Attribute bgp.go PathAttributeAigp.DecodeFromBytes buffer overflow
Published 2026-05-04 · Analyzed
7.5EPSS 0.006
CVE-2026-37461
An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
Published 2026-05-04 · Analyzed
7.5EPSS 0.006
CVE-2026-41643
GoBGP: Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE
Published 2026-05-07 · Analyzed
7.5EPSS 0.006
CVE-2026-41642
GoBGP: Remote Denial of Service (Panic) via Malformed Well-known Path Attribute
Published 2026-05-07 · Analyzed
7.5EPSS 0.006
CVE-2026-42285
GoBGP: Panic in AdjRib.Update via malformed BGP Update message (Nil Pointer Dereference)
Published 2026-05-07 · Analyzed
7.5EPSS 0.006
CVE-2025-43972
An issue was discovered in GoBGP before 3.35.0. An attacker can cause a crash in the pkg/packet/bgp/bgp.go flowspec parser by sending fewer than 20 bytes in a certain context.
Published 2025-04-21 · Analyzed
7.5EPSS 0.006
CVE-2026-30405
An issue in GoBGP gobgpd v.4.2.0 allows a remote attacker to cause a denial of service via the NEXT_HOP path attribute
Published 2026-03-16 · Analyzed
7.5EPSS 0.005
CVE-2026-5123
osrg GoBGP bgp.go DecodeFromBytes off-by-one
Published 2026-03-30 · Analyzed
6.3EPSS 0.007
CVE-2026-5122
osrg GoBGP BGP OPEN Message bgp.go DecodeFromBytes access control
Published 2026-03-30 · Analyzed
6.3EPSS 0.005
CVE-2026-5124
osrg GoBGP BGP Header bgp.go BGPHeader.DecodeFromBytes access control
Published 2026-03-30 · Analyzed
6.3EPSS 0.005
CVE-2025-43970
An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by ensuring that there are 12 bytes or 36 bytes (depending on the address family).
Published 2025-04-21 · Analyzed
5.3EPSS 0.004