PT-2026-29046 · Osrg+1 · Gobgp+1

·

CVE-2026-5123

·

Published

2026-01-01

·

Updated

2026-08-24

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions osrg GoBGP versions through 4.3.0
Description A weakness exists in the DecodeFromBytes function within the pkg/packet/bgp/bgp.go file of osrg GoBGP. Manipulating the data[1] argument can lead to an off-by-one error. The attack can be launched remotely and is considered highly complex with difficult exploitability. The identified patch is 67c059413470df64bc20801c46f64058e88f800f.
Recommendations Apply the patch 67c059413470df64bc20801c46f64058e88f800f to address the issue.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14521
CVE-2026-5123

Affected Products

Gobgp
Red Os