osrg has 11 CVEs on record between 2024 and 2026. Disclosures have slowed: 2 in the last 90 days after 6 in the 90 before. The busiest recent month was May 2026 with 4. The median CVSS is 7.3 (high). None have a confirmed exploitation report. Most affected products: github.com/osrg/gobgp/v4 (6), github.com/osrg/gobgp/v3 (2), gobgp (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.3
- Publish → KEV
- —
- Last 90 days
- 2 prev 6
Products
- github.com/osrg/gobgp/v4 6
- github.com/osrg/gobgp/v3 2
- gobgp 2
- github.com/osrg/gobgp 1
Worst active — by depth score
CVE-2025-43971High· 8.6GoBGP panics due to a zero value for softwareVersionLen47CVE-2026-37461High· 7.5GoBGP has an out-of-bounds read in the ParseIP6Extended function41CVE-2026-41643High· 7.5GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE41CVE-2026-30405High· 7.5GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute41CVE-2023-46565High· 7.5Buffer Overflow vulnerability in osrg gobgp41
osrg vulnerabilities
CVEs affecting osrg, newest first. Open any entry for full detail, references, and exploit status.
11 CVEsRSS
CVE-2026-49837Medium· 5.9GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Versions prior to 4.6.0 contain a BGP OPEN capability parsing issue where several concrete capability decoders may parse data from the f…
CVE-2026-49838Medium· 5.9GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.7.0, GoBGP accepts a zero-length AS_PATH during UPDATE decoding and later panics while validating that attribute for …
CVE-2026-37462High· 7.3GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes function
GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes function
CVE-2026-37461High· 7.5GoBGP has an out-of-bounds read in the ParseIP6Extended function
GoBGP has an out-of-bounds read in the ParseIP6Extended function
CVE-2026-7737Medium· 5.3GoBGP has Improper Restriction of Operations within the Bounds of a Memory Buffer
GoBGP has Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE-2026-7734Medium· 5.3GoBGP has an Improper Resource Shutdown or Release
GoBGP has an Improper Resource Shutdown or Release
CVE-2026-7736High· 7.3GoBGP has an Integer Underflow Issue
GoBGP has an Integer Underflow Issue
CVE-2026-41643High· 7.5GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE
GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE
CVE-2026-30405High· 7.5GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute
GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute
CVE-2025-43971High· 8.6GoBGP panics due to a zero value for softwareVersionLen
GoBGP panics due to a zero value for softwareVersionLen
CVE-2023-46565High· 7.5Buffer Overflow vulnerability in osrg gobgp
Buffer Overflow vulnerability in osrg gobgp