ZeroHour

Vulnerabilities

16 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-41643
+2 in the same advisory: …41642 …42285
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language.

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP where a malformed BGP UPDATE message can trigger a runtime error: index out of range panic. This occurs during the processing of 4-byte AS attributes when the message structure causes an internal slice index shift that is not properly handled. This issue has been patched in version 4.3.0.

NVD description · AI analysis pending
7.5<1% PoC
  • osrg gobgp
CVE-2026-37461
+4 in the same advisory: …7737 …7734 …7736 …7735
An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted

An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

NVD description · AI analysis pending
7.5
group max
<1%
  • osrg gobgp
CVE-2026-5123
+2 in the same advisory: …5122 …5124
A weakness has been identified in osrg GoBGP up to 4.3.0.

A weakness has been identified in osrg GoBGP up to 4.3.0. This impacts the function DecodeFromBytes of the file pkg/packet/bgp/bgp.go. Executing a manipulation of the argument data[1] can lead to off-by-one. The attack may be launched remotely. Attacks of this nature are highly complex. The exploitability is said to be difficult. This patch is called 67c059413470df64bc20801c46f64058e88f800f. A patch should be applied to remediate this issue.

NVD description · AI analysis pending
6.3<1%
  • osrg gobgp
CVE-2026-30405
An issue in GoBGP gobgpd v.4.2.0 allows a remote attacker to cause a denial of service via the NEXT_HOP path attribute

An issue in GoBGP gobgpd v.4.2.0 allows a remote attacker to cause a denial of service via the NEXT_HOP path attribute

NVD description · AI analysis pending
7.5<1% PoC
  • osrg gobgp
CVE-2025-43973
+3 in the same advisory: …43972 …43971 …43970
An issue was discovered in GoBGP before 3.35.0.

An issue was discovered in GoBGP before 3.35.0. pkg/packet/rtr/rtr.go does not verify that the input length corresponds to a situation in which all bytes are available for an RTR message.

NVD description · AI analysis pending
9.8
group max
<1%
  • osrg gobgp