CVE-2026-7736High· 7.3▾ TwilightGoBGP has an Integer Underflow Issue
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry of the file pkg/packet/mrt/mrt.go. Executing a manipulation can lead to integer underflow. It is possible to launch the attack remotely. Upgrading to version 4.4.0 addresses this issue. This patch is called 76d911046344a3923cbe573364197aa081944592. It is suggested to upgrade the affected component.
github.com/osrg/gobgp/v4 < 4.4.0Upgrade to a patched release:
github.com/osrg/gobgp/v4 4.4.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-41642High· 7.5github.com/osrg/gobgp: GoBGP: Denial of Service via malformed BGP UPDATE message (CVE-2026-41642)
CVE-2026-7734Medium· 5.3GoBGP has an Improper Resource Shutdown or Release
CVE-2026-30405High· 7.5GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute
CVE-2026-37462High· 7.3GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes function
CVE-2026-42285High· 7.5github.com/osrg/gobgp: GoBGP: Denial of Service due to specially crafted BGP UPDATE message (CVE-2026-42285)
CVE-2026-41643High· 7.5GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE