CVE-2026-7735
osrg GoBGP AIGP Attribute bgp.go PathAttributeAigp.DecodeFromBytes buffer overflow
CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was found in osrg GoBGP up to 4.3.0. Affected is the function PathAttributeAigp.DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component AIGP Attribute Parser. Performing a manipulation results in buffer overflow. It is possible to initiate the attack remotely. Upgrading to version 4.4.0 is able to address this issue. The patch is named 51ad1ada06cb41ce47b7066799981816f50b7ced. The affected component should be upgraded.
| CWE | CWE-120 CWE-119 |
| Vendor | osrg |
| Product | gobgp |
| Published | May 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for osrg gobgp
Be the first to know when new high vulnerabilities affecting osrg gobgp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
osrg / GoBGP
4.0 4.1 4.2 4.3.0
References
vuldb.com: https://vuldb.com/vuln/360910 vuldb.com: https://vuldb.com/vuln/360910/cti vuldb.com: https://vuldb.com/submit/807600 github.com: https://github.com/osrg/gobgp/commit/51ad1ada06cb41ce47b7066799981816f50b7ced github.com: https://github.com/osrg/gobgp/releases/tag/v4.4.0 github.com: https://github.com/osrg/gobgp/
Credits
๐ rensiru (VulDB User)