CVE-2026-49837
GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Versions prior to 4.6.0 contain a BGP OPEN capability parsing issue where several concrete capability decoders may parse data from the full remaining capability buffer instead of the slice bounded by the declared capability length, `CapLen`. A malformed BGP OPEN message can cause bytes from a following capability to be interpreted as part of the current capability. The most security-relevant case is the 4-octet AS capability, where a capability with `CapLen == 0` may cause the parser to read bytes from the following capability as the 4-octet AS value. This parsed value may later affect peer AS validation during BGP session establishment. Version 4.6.0 patches the issue.
| CWE | CWE-125 |
| Vendor | osrg |
| Product | gobgp |
| Published | Sep 10, 2026 |
| Last Updated | Sep 15, 2026 |
Get instant alerts for osrg gobgp
Be the first to know when new medium vulnerabilities affecting osrg gobgp are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N