Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

osrg — Vulnerabilities & Security Advisories 13

Browse all 13 CVE security advisories affecting osrg. AI-powered Chinese analysis, POCs, and references for each vulnerability.

OSRG develops open-source networking and virtualization software, primarily focused on virtual switch and network function virtualization solutions. Historically, their products have been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from improper input validation and access control flaws. While no major public security incidents have been widely documented, the 11 CVEs on record highlight persistent security concerns in their codebase, particularly around memory corruption and boundary condition issues. Their software's critical infrastructure role makes these vulnerabilities potentially impactful, though the company has generally addressed reported issues through timely patches and security updates.

Top products by osrg: GoBGP
CVE ID Title CVSS Severity Published
CVE-2026-49838 GoBGP confederation validation panics on empty AS_PATH attribute — gobgp CWE-129 5.9 Medium 2026-09-10
CVE-2026-49837 GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries — gobgp CWE-125 5.9 Medium 2026-09-10
CVE-2026-41643 GoBGP: Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE — gobgp CWE-129 7.5 High 2026-05-07
CVE-2026-42285 GoBGP: Panic in AdjRib.Update via malformed BGP Update message (Nil Pointer Dereference) — gobgp CWE-476 7.5 High 2026-05-07
CVE-2026-41642 GoBGP: Remote Denial of Service (Panic) via Malformed Well-known Path Attribute — gobgp CWE-476 7.5 High 2026-05-07
CVE-2026-7737 osrg GoBGP BMP Parser bmp.go BMPStatisticsReport.ParseBody out-of-bounds — GoBGP CWE-125 5.3 Medium 2026-05-04
CVE-2026-7736 osrg GoBGP mrt.go parseRibEntry integer underflow — GoBGP CWE-191 7.3 High 2026-05-04
CVE-2026-7735 osrg GoBGP AIGP Attribute bgp.go PathAttributeAigp.DecodeFromBytes buffer overflow — GoBGP CWE-120 7.3 High 2026-05-04
CVE-2026-7734 osrg GoBGP SRv6 L3 Service prefix_sid.go SRv6L3ServiceAttribute.DecodeFromBytes denial of service — GoBGP CWE-404 5.3 Medium 2026-05-04
CVE-2026-5124 osrg GoBGP BGP Header bgp.go BGPHeader.DecodeFromBytes access control — GoBGP CWE-284 3.7 Low 2026-03-30
CVE-2026-5123 osrg GoBGP bgp.go DecodeFromBytes off-by-one — GoBGP CWE-193 3.7 Low 2026-03-30
CVE-2026-5122 osrg GoBGP BGP OPEN Message bgp.go DecodeFromBytes access control — GoBGP CWE-284 3.7 Low 2026-03-30
CVE-2025-7464 osrg GoBGP rtr.go SplitRTR out-of-bounds — GoBGP CWE-125 3.7 Low 2025-07-12

This page lists every published CVE security advisory associated with osrg. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.