Search CVE reports


Toggle filters

1 – 10 of 20 results


CVE-2026-49837

Medium priority
Needs evaluation

[Unknown description]

1 affected package

gobgp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gobgp Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-37462

Medium priority
Needs evaluation

(An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/b ...)

1 affected package

gobgp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gobgp Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-42285

Medium priority
Not affected

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.4.0, an unauthenticated remote BGP peer can trigger a fatal panic in GoBGP by sending a specially crafted BGP UPDATE...

1 affected package

gobgp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gobgp Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-41643

Medium priority

Some fixes available 5 of 6

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP where a malformed BGP UPDATE message can...

1 affected package

gobgp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gobgp Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-41642

Medium priority
Not affected

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP due to a nil pointer dereference. When...

1 affected package

gobgp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gobgp Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-37461

Medium priority

Some fixes available 5 of 6

An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

1 affected package

gobgp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gobgp Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-7737

Medium priority

Some fixes available 5 of 6

A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by this issue is the function BMPPeerUpNotification.ParseBody/BMPStatisticsReport.ParseBody of the file pkg/packet/bmp/bmp.go of the component BMP Parser. The...

1 affected package

gobgp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gobgp Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-7736

Medium priority

Some fixes available 5 of 6

A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry of the file pkg/packet/mrt/mrt.go. Executing a manipulation can lead to integer underflow. It is possible to...

1 affected package

gobgp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gobgp Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-7735

Medium priority

Some fixes available 5 of 6

A vulnerability was found in osrg GoBGP up to 4.3.0. Affected is the function PathAttributeAigp.DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component AIGP Attribute Parser. Performing a manipulation results in buffer...

1 affected package

gobgp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gobgp Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-7734

Medium priority

Some fixes available 3 of 4

A vulnerability has been found in osrg GoBGP up to 4.3.0. This impacts the function SRv6L3ServiceAttribute.DecodeFromBytes of the file pkg/packet/bgp/prefix_sid.go of the component SRv6 L3 Service. Such manipulation of the...

1 affected package

gobgp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gobgp Fixed Fixed Fixed Not affected Not affected
Show less packages