Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

GoBGP — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in GoBGP, with AI-generated Chinese analysis, references, and POCs.

This page documents the Common Weakness Enumerations associated with GoBGP, an open-source BGP software router developed by Open Source Laboratory. It aggregates security data covering vulnerabilities reported in GoBGP from its initial public releases through recent patches, providing a comprehensive historical view of its security posture. Here, you can discover detailed records of reported advisories, allowing you to track how the vendor addresses specific flaws over time. You can also understand the technical nuances of weakness classes that frequently affect this application, such as configuration errors or input validation failures. Furthermore, the page serves as a lookup tool for the product's vulnerability history, enabling security teams to assess risk exposure, verify patch applicability, and correlate internal incidents with external disclosures. By centralizing this information, the resource helps developers and administrators identify patterns in defect reporting and prioritize remediation efforts based on the severity and prevalence of each issue. This collection aims to provide transparency into the software’s security lifecycle, supporting informed decision-making for deployment and maintenance without promoting any specific vendor narrative or commercial interest.

Vendor: GoBGP

CVE IDTitleCVSSSeverityPublished
CVE-2026-41643 GoBGP: Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE CWE-129 7.5 High2026-05-07
CVE-2026-42285 GoBGP: Panic in AdjRib.Update via malformed BGP Update message (Nil Pointer Dereference) CWE-476 7.5 High2026-05-07
CVE-2026-41642 GoBGP: Remote Denial of Service (Panic) via Malformed Well-known Path Attribute CWE-476 7.5 High2026-05-07
CVE-2026-7737 osrg GoBGP BMP Parser bmp.go BMPStatisticsReport.ParseBody out-of-bounds CWE-125 5.3 Medium2026-05-04
CVE-2026-7736 osrg GoBGP mrt.go parseRibEntry integer underflow CWE-191 7.3 High2026-05-04
CVE-2026-7735 osrg GoBGP AIGP Attribute bgp.go PathAttributeAigp.DecodeFromBytes buffer overflow CWE-120 7.3 High2026-05-04
CVE-2026-7734 osrg GoBGP SRv6 L3 Service prefix_sid.go SRv6L3ServiceAttribute.DecodeFromBytes denial of service CWE-404 5.3 Medium2026-05-04
CVE-2026-5124 osrg GoBGP BGP Header bgp.go BGPHeader.DecodeFromBytes access control CWE-284 3.7 Low2026-03-30
CVE-2026-5123 osrg GoBGP bgp.go DecodeFromBytes off-by-one CWE-193 3.7 Low2026-03-30
CVE-2026-5122 osrg GoBGP BGP OPEN Message bgp.go DecodeFromBytes access control CWE-284 3.7 Low2026-03-30
CVE-2025-7464 osrg GoBGP rtr.go SplitRTR out-of-bounds CWE-125 3.7 Low2025-07-12
CVE-2025-43971 GoBGP 安全漏洞 CWE-193 8.6 High2025-04-21
CVE-2025-43970 GoBGP 安全漏洞 CWE-1284 4.3 Medium2025-04-21
CVE-2025-43973 GoBGP 安全漏洞 CWE-193 6.8 Medium2025-04-21
CVE-2025-43972 GoBGP 安全漏洞 CWE-1284 6.8 Medium2025-04-21

All 15 known CVE vulnerabilities affecting GoBGP with full Chinese analysis, references, and POCs where available.