๐Ÿ” CVE Alert

CVE-2026-7735

HIGH 7.3

osrg GoBGP AIGP Attribute bgp.go PathAttributeAigp.DecodeFromBytes buffer overflow

CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was found in osrg GoBGP up to 4.3.0. Affected is the function PathAttributeAigp.DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component AIGP Attribute Parser. Performing a manipulation results in buffer overflow. It is possible to initiate the attack remotely. Upgrading to version 4.4.0 is able to address this issue. The patch is named 51ad1ada06cb41ce47b7066799981816f50b7ced. The affected component should be upgraded.

CWE CWE-120 CWE-119
Vendor osrg
Product gobgp
Published May 4, 2026
Stay Ahead of the Next One

Get instant alerts for osrg gobgp

Be the first to know when new high vulnerabilities affecting osrg gobgp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

osrg / GoBGP
4.0 4.1 4.2 4.3.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/360910 vuldb.com: https://vuldb.com/vuln/360910/cti vuldb.com: https://vuldb.com/submit/807600 github.com: https://github.com/osrg/gobgp/commit/51ad1ada06cb41ce47b7066799981816f50b7ced github.com: https://github.com/osrg/gobgp/releases/tag/v4.4.0 github.com: https://github.com/osrg/gobgp/

Credits

๐Ÿ” rensiru (VulDB User)