Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 8

Количество 8

fstec логотип

BDU:2026-14524

4 месяца назад

Уязвимость парсера BGP OPEN-сообщений модуля pkg/packet/bgp протокола пограничного шлюза GoBGP, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2026-49837

7 дней назад

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Versions prior to 4.6.0 contain a BGP OPEN capability parsing issue where several concrete capability decoders may parse data from the full remaining capability buffer instead of the slice bounded by the declared capability length, `CapLen`. A malformed BGP OPEN message can cause bytes from a following capability to be interpreted as part of the current capability. The most security-relevant case is the 4-octet AS capability, where a capability with `CapLen == 0` may cause the parser to read bytes from the following capability as the 4-octet AS value. This parsed value may later affect peer AS validation during BGP session establishment. Version 4.6.0 patches the issue.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2026-49837

7 дней назад

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Versions prior to 4.6.0 contain a BGP OPEN capability parsing issue where several concrete capability decoders may parse data from the full remaining capability buffer instead of the slice bounded by the declared capability length, `CapLen`. A malformed BGP OPEN message can cause bytes from a following capability to be interpreted as part of the current capability. The most security-relevant case is the 4-octet AS capability, where a capability with `CapLen == 0` may cause the parser to read bytes from the following capability as the 4-octet AS value. This parsed value may later affect peer AS validation during BGP session establishment. Version 4.6.0 patches the issue.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2026-49837

7 дней назад

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Versions prior to 4.6.0 contain a BGP OPEN capability parsing issue where several concrete capability decoders may parse data from the full remaining capability buffer instead of the slice bounded by the declared capability length, `CapLen`. A malformed BGP OPEN message can cause bytes from a following capability to be interpreted as part of the current capability. The most security-relevant case is the 4-octet AS capability, where a capability with `CapLen == 0` may cause the parser to read bytes from the following capability as the 4-octet AS value. This parsed value may later affect peer AS validation during BGP session establishment. Version 4.6.0 patches the issue.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2026-49837

7 дней назад

GoBGP is an open source Border Gateway Protocol (BGP) implementation i ...

CVSS3: 5.9
EPSS: Низкий
redos логотип

ROS-20260819-80-0039

30 дней назад

Уязвимость gobgp

CVSS2: 7.1
EPSS: Низкий
redos логотип

ROS-20260819-73-0039

30 дней назад

Уязвимость gobgp

CVSS2: 7.1
EPSS: Низкий
github логотип

GHSA-gjrg-jjr3-56cm

2 месяца назад

GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-14524

Уязвимость парсера BGP OPEN-сообщений модуля pkg/packet/bgp протокола пограничного шлюза GoBGP, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 5.9
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2026-49837

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Versions prior to 4.6.0 contain a BGP OPEN capability parsing issue where several concrete capability decoders may parse data from the full remaining capability buffer instead of the slice bounded by the declared capability length, `CapLen`. A malformed BGP OPEN message can cause bytes from a following capability to be interpreted as part of the current capability. The most security-relevant case is the 4-octet AS capability, where a capability with `CapLen == 0` may cause the parser to read bytes from the following capability as the 4-octet AS value. This parsed value may later affect peer AS validation during BGP session establishment. Version 4.6.0 patches the issue.

CVSS3: 5.9
0%
Низкий
7 дней назад
redhat логотип
CVE-2026-49837

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Versions prior to 4.6.0 contain a BGP OPEN capability parsing issue where several concrete capability decoders may parse data from the full remaining capability buffer instead of the slice bounded by the declared capability length, `CapLen`. A malformed BGP OPEN message can cause bytes from a following capability to be interpreted as part of the current capability. The most security-relevant case is the 4-octet AS capability, where a capability with `CapLen == 0` may cause the parser to read bytes from the following capability as the 4-octet AS value. This parsed value may later affect peer AS validation during BGP session establishment. Version 4.6.0 patches the issue.

CVSS3: 7.4
0%
Низкий
7 дней назад
nvd логотип
CVE-2026-49837

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Versions prior to 4.6.0 contain a BGP OPEN capability parsing issue where several concrete capability decoders may parse data from the full remaining capability buffer instead of the slice bounded by the declared capability length, `CapLen`. A malformed BGP OPEN message can cause bytes from a following capability to be interpreted as part of the current capability. The most security-relevant case is the 4-octet AS capability, where a capability with `CapLen == 0` may cause the parser to read bytes from the following capability as the 4-octet AS value. This parsed value may later affect peer AS validation during BGP session establishment. Version 4.6.0 patches the issue.

CVSS3: 5.9
0%
Низкий
7 дней назад
debian логотип
CVE-2026-49837

GoBGP is an open source Border Gateway Protocol (BGP) implementation i ...

CVSS3: 5.9
0%
Низкий
7 дней назад
redos логотип
ROS-20260819-80-0039

Уязвимость gobgp

CVSS2: 7.1
0%
Низкий
30 дней назад
redos логотип
ROS-20260819-73-0039

Уязвимость gobgp

CVSS2: 7.1
0%
Низкий
30 дней назад
github логотип
GHSA-gjrg-jjr3-56cm

GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries

CVSS3: 5.9
0%
Низкий
2 месяца назад

Уязвимостей на страницу