Home

Description

An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

PUBLISHED Reserved 2026-04-06 | Published 2026-05-04 | Updated 2026-05-05 | Assigner mitre

References

github.com/osrg/gobgp/blob/v4.3.0/pkg/packet/bgp/bgp.go

github.com/...ommit/362cce3e325f56e7a4f792ccb9689b3bdda9e682

github.com/...ommit/9ce8936672ebc07df524da77fa4c6ae26d92be6d

cve.org (CVE-2026-37461)

nvd.nist.gov (CVE-2026-37461)

Download JSON