CVE-2026-49838Medium· 5.9▾ SunlitGoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.7.0, GoBGP accepts a zero-length AS_PATH during UPDATE decoding and later panics while validating that attribute for …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.7.0, GoBGP accepts a zero-length AS_PATH during UPDATE decoding and later panics while validating that attribute for a confederation eBGP peer. The vulnerable path is in the BGP UPDATE validator: a malformed UPDATE that should be rejected as a malformed AS_PATH instead reaches an unchecked p.Value[0] access, allowing a configured confederation eBGP peer to trigger a denial of service. Version 4.7.0 patches the issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/osrg/gobgp/v4 <= 4.6.0Patched in:
github.com/osrg/gobgp/v4 4.7.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-49837Medium· 5.9GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language
CVE-2026-62866Medium· 6.2Dasel is a command-line tool and library for querying, modifying, and transforming data structures
CVE-2025-43971High· 8.6GoBGP panics due to a zero value for softwareVersionLen
CVE-2026-30405High· 7.5GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute
CVE-2026-84445High· 8.7gRPC-Go is the Go language implementation of gRPC
CVE-2023-2008High· 8.2A flaw was found in the Linux kernel's udmabuf device driver, within a fault handler