PT-2026-37136 · Gobgp · Gobgp

Bacon251

·

Published

2026-04-29

·

Updated

2026-05-07

·

CVE-2026-41643

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GoBGP versions prior to 4.3.0
Description A remote Denial of Service (DoS) issue exists where a malformed BGP UPDATE message can trigger a runtime error resulting in an index out of range panic. This occurs during the processing of 4-byte AS attributes within the UpdatePathAttrs4ByteAs() function located in internal/pkg/table/message.go. When a BGP UPDATE message contains both an AS PATH and an AS4 PATH attribute, and the AS4 PATH (Type 17) appears before the AS PATH (Type 2) and is malformed, the software attempts to remove the AS4 PATH from the msg.PathAttributes slice. This deletion causes subsequent attributes to shift left, but the function continues to use a stale index to update the AS PATH, leading to a process crash.
Recommendations Update to version 4.3.0.

Exploit

Fix

DoS

Improper Validation of Array Index

Weakness Enumeration

Related Identifiers

CVE-2026-41643
GHSA-8RXH-R2P6-7F2Q

Affected Products

Gobgp