PT-2026-37135 · Gobgp · Gobgp

Bacon251

·

Published

2026-04-29

·

Updated

2026-05-07

·

CVE-2026-41642

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GoBGP versions prior to 4.4.0
Description A remote Denial of Service (DoS) issue exists due to a nil pointer dereference. When a malformed BGP UPDATE message contains an unrecognized Path Attribute marked as "Well-known," the daemon fails to interrupt the message handling flow. This leads to an illegal memory access and a full process crash (panic) instead of simply closing the affected session. The issue is located in the Finite State Machine (FSM) message handling loop within the recvMessageloop() function in the pkg/server/fsm.go file.
Recommendations Update to version 4.4.0.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41642
GHSA-7235-89M6-F4PX

Affected Products

Gobgp