6.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X
Description
A weakness has been identified in osrg GoBGP up to 4.3.0. This impacts the function DecodeFromBytes of the file pkg/packet/bgp/bgp.go. Executing a manipulation of the argument data[1] can lead to off-by-one. The attack may be launched remotely. Attacks of this nature are highly complex. The exploitability is said to be difficult. This patch is called 67c059413470df64bc20801c46f64058e88f800f. A patch should be applied to remediate this issue.
Basic Information
ID
CVE-2026-5123
Source
VulDB
Published
Mar 30, 2026 at 15:15
Modified
Apr 1, 2026 at 18:10
Affected Product
Vendor
osrg
Product
GoBGP
Version
4.0
Affected Versions
osrg GoBGP 4.0
osrg GoBGP 4.1
osrg GoBGP 4.2
osrg GoBGP 4.3.0
osrg GoBGP 4.1
osrg GoBGP 4.2
osrg GoBGP 4.3.0