PT-2026-29046 · Osrg · Gobgp

Sunxj

·

Published

2026-01-01

·

Updated

2026-03-31

·

CVE-2026-5123

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions osrg GoBGP versions through 4.3.0
Description A weakness exists in the DecodeFromBytes function within the pkg/packet/bgp/bgp.go file of osrg GoBGP. Manipulating the data[1] argument can lead to an off-by-one error. The attack can be launched remotely and is considered highly complex with difficult exploitability. The identified patch is 67c059413470df64bc20801c46f64058e88f800f.
Recommendations Apply the patch 67c059413470df64bc20801c46f64058e88f800f to address the issue.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-5123

Affected Products

Gobgp