Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

GoBGP — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in GoBGP, with AI-generated Chinese analysis, references, and POCs.

This page details security vulnerabilities associated with GoBGP, an open-source Border Gateway Protocol implementation developed by the Japanese telecommunications company NRI. It serves as a centralized resource for tracking and analyzing security weaknesses specific to this routing software solution. The collection aggregates confirmed vulnerabilities identified in the GoBGP codebase, encompassing issues ranging from critical remote code execution flaws to less severe information disclosure and denial-of-service conditions. This dataset covers reported security incidents from the initial public releases of the project through recent patches, providing a comprehensive historical view of the software's security posture over time. Users can utilize this page to monitor vendor advisories issued by the GoBGP maintainers, gaining insight into how the development team responds to emerging threats. It allows security professionals to understand the nature of prevalent weakness classes within the BGP stack, facilitating better risk assessment for network infrastructure deployments. Additionally, administrators can look up the specific vulnerability history of GoBGP versions to determine patching priorities and compliance requirements for their systems. By reviewing the documented exploits and mitigation strategies, teams can strengthen their network security policies and ensure that routing protocols remain resilient against known attack vectors. This resource supports proactive security management by offering a clear overview of past incidents and their resolutions, helping organizations maintain the integrity and availability of their inter-domain routing operations without relying on fragmented or outdated information sources.

Vendor: GoBGP

CVE IDTitleCVSSSeverityPublished
CVE-2026-41643 GoBGP: Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE CWE-129 7.5 High2026-05-07
CVE-2026-42285 GoBGP: Panic in AdjRib.Update via malformed BGP Update message (Nil Pointer Dereference) CWE-476 7.5 High2026-05-07
CVE-2026-41642 GoBGP: Remote Denial of Service (Panic) via Malformed Well-known Path Attribute CWE-476 7.5 High2026-05-07
CVE-2026-7737 osrg GoBGP BMP Parser bmp.go BMPStatisticsReport.ParseBody out-of-bounds CWE-125 5.3 Medium2026-05-04
CVE-2026-7736 osrg GoBGP mrt.go parseRibEntry integer underflow CWE-191 7.3 High2026-05-04
CVE-2026-7735 osrg GoBGP AIGP Attribute bgp.go PathAttributeAigp.DecodeFromBytes buffer overflow CWE-120 7.3 High2026-05-04
CVE-2026-7734 osrg GoBGP SRv6 L3 Service prefix_sid.go SRv6L3ServiceAttribute.DecodeFromBytes denial of service CWE-404 5.3 Medium2026-05-04
CVE-2026-5124 osrg GoBGP BGP Header bgp.go BGPHeader.DecodeFromBytes access control CWE-284 3.7 Low2026-03-30
CVE-2026-5123 osrg GoBGP bgp.go DecodeFromBytes off-by-one CWE-193 3.7 Low2026-03-30
CVE-2026-5122 osrg GoBGP BGP OPEN Message bgp.go DecodeFromBytes access control CWE-284 3.7 Low2026-03-30
CVE-2025-7464 osrg GoBGP rtr.go SplitRTR out-of-bounds CWE-125 3.7 Low2025-07-12
CVE-2025-43971 GoBGP 安全漏洞 CWE-193 8.6 High2025-04-21
CVE-2025-43970 GoBGP 安全漏洞 CWE-1284 4.3 Medium2025-04-21
CVE-2025-43973 GoBGP 安全漏洞 CWE-193 6.8 Medium2025-04-21
CVE-2025-43972 GoBGP 安全漏洞 CWE-1284 6.8 Medium2025-04-21

All 15 known CVE vulnerabilities affecting GoBGP with full Chinese analysis, references, and POCs where available.