Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-49838

Опубликовано: 10 сент. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.7.0, GoBGP accepts a zero-length AS_PATH during UPDATE decoding and later panics while validating that attribute for a confederation eBGP peer. The vulnerable path is in the BGP UPDATE validator: a malformed UPDATE that should be rejected as a malformed AS_PATH instead reaches an unchecked p.Value[0] access, allowing a configured confederation eBGP peer to trigger a denial of service. Version 4.7.0 patches the issue.

A flaw was found in GoBGP, an open-source Border Gateway Protocol (BGP) implementation. A configured confederation eBGP peer can send a specially crafted BGP UPDATE message with a zero-length AS_PATH attribute. This malformed message is improperly handled during validation, leading to an unchecked memory access that causes the GoBGP process to crash. This vulnerability results in a denial of service for the affected system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4/metallb-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2531686github.com/osrg/gobgp: GoBGP: Denial of Service via malformed BGP UPDATE message

EPSS

Процентиль: 27%
0.00333
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
7 дней назад

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.7.0, GoBGP accepts a zero-length AS_PATH during UPDATE decoding and later panics while validating that attribute for a confederation eBGP peer. The vulnerable path is in the BGP UPDATE validator: a malformed UPDATE that should be rejected as a malformed AS_PATH instead reaches an unchecked `p.Value[0]` access, allowing a configured confederation eBGP peer to trigger a denial of service. Version 4.7.0 patches the issue.

CVSS3: 5.9
nvd
7 дней назад

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.7.0, GoBGP accepts a zero-length AS_PATH during UPDATE decoding and later panics while validating that attribute for a confederation eBGP peer. The vulnerable path is in the BGP UPDATE validator: a malformed UPDATE that should be rejected as a malformed AS_PATH instead reaches an unchecked `p.Value[0]` access, allowing a configured confederation eBGP peer to trigger a denial of service. Version 4.7.0 patches the issue.

CVSS3: 5.9
debian
7 дней назад

GoBGP is an open source Border Gateway Protocol (BGP) implementation i ...

redos
30 дней назад

Уязвимость gobgp

redos
30 дней назад

Уязвимость gobgp

EPSS

Процентиль: 27%
0.00333
Низкий

5.9 Medium

CVSS3