Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

GoBGP — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in GoBGP, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerabilities for the GoBGP product within the context of network security tooling. It collects known security flaws, including buffer overflows, race conditions, and logic errors, covering advisories published over the last five years. Readers can use this resource to track the vendor's security updates, understand the specific class of weaknesses affecting this routing software, and review the product's vulnerability history to assess risk exposure. The data is filtered by the specific weakness type and product identifier, allowing for focused analysis of security trends. This aggregation supports compliance reviews and security operations by providing a consolidated view of reported issues without requiring manual searches across multiple databases. The interface presents each entry with its severity rating, affected versions, and patch availability. Users can filter results by date, impact, or CVSS score to prioritize remediation efforts. This structured overview helps teams maintain an up-to-date understanding of the security posture of GoBGP, ensuring that critical updates are not missed during routine maintenance cycles.

Vendor: GoBGP

CVE ID Title CVSS Severity Published
CVE-2026-49838 GoBGP confederation validation panics on empty AS_PATH attribute CWE-129 5.9 Medium 2026-09-10
CVE-2026-49837 GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries CWE-125 5.9 Medium 2026-09-10
CVE-2026-41643 GoBGP: Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE CWE-129 7.5 High 2026-05-07
CVE-2026-42285 GoBGP: Panic in AdjRib.Update via malformed BGP Update message (Nil Pointer Dereference) CWE-476 7.5 High 2026-05-07
CVE-2026-41642 GoBGP: Remote Denial of Service (Panic) via Malformed Well-known Path Attribute CWE-476 7.5 High 2026-05-07
CVE-2026-7737 osrg GoBGP BMP Parser bmp.go BMPStatisticsReport.ParseBody out-of-bounds CWE-125 5.3 Medium 2026-05-04
CVE-2026-7736 osrg GoBGP mrt.go parseRibEntry integer underflow CWE-191 7.3 High 2026-05-04
CVE-2026-7735 osrg GoBGP AIGP Attribute bgp.go PathAttributeAigp.DecodeFromBytes buffer overflow CWE-120 7.3 High 2026-05-04
CVE-2026-7734 osrg GoBGP SRv6 L3 Service prefix_sid.go SRv6L3ServiceAttribute.DecodeFromBytes denial of service CWE-404 5.3 Medium 2026-05-04
CVE-2026-5124 osrg GoBGP BGP Header bgp.go BGPHeader.DecodeFromBytes access control CWE-284 3.7 Low 2026-03-30
CVE-2026-5123 osrg GoBGP bgp.go DecodeFromBytes off-by-one CWE-193 3.7 Low 2026-03-30
CVE-2026-5122 osrg GoBGP BGP OPEN Message bgp.go DecodeFromBytes access control CWE-284 3.7 Low 2026-03-30
CVE-2025-7464 osrg GoBGP rtr.go SplitRTR out-of-bounds CWE-125 3.7 Low 2025-07-12
CVE-2025-43971 GoBGP 安全漏洞 CWE-193 8.6 High 2025-04-21
CVE-2025-43972 GoBGP 安全漏洞 CWE-1284 6.8 Medium 2025-04-21
CVE-2025-43973 GoBGP 安全漏洞 CWE-193 6.8 Medium 2025-04-21
CVE-2025-43970 GoBGP 安全漏洞 CWE-1284 4.3 Medium 2025-04-21

All 17 known CVE vulnerabilities affecting GoBGP with full Chinese analysis, references, and POCs where available.