CVE 6.3 MEDIUM

osrg GoBGP BGP Header bgp.go BGPHeader.DecodeFromBytes access control_CVE-2026-5124

6.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X

Description

A security vulnerability has been detected in osrg GoBGP up to 4.3.0. Affected is the function BGPHeader.DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component BGP Header Handler. The manipulation leads to improper access controls. Remote exploitation of the attack is possible. The attack is considered to have high complexity. The exploitability is told to be difficult. The identifier of the patch is f0f24a2a901cbf159260698211ab15c583ced131. To fix this issue, it is recommended to deploy a patch.

Basic Information

ID CVE-2026-5124
Source VulDB
Published Mar 30, 2026 at 16:15
Modified Mar 30, 2026 at 18:39

Affected Product

Vendor osrg
Product GoBGP
Version 4.0
Affected Versions osrg GoBGP 4.0
osrg GoBGP 4.1
osrg GoBGP 4.2
osrg GoBGP 4.3.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.