CVE-2026-49837 PUBLISHED

GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries

Assigner: GitHub_M
Reserved: 01.06.2026 Published: 10.09.2026 Updated: 10.09.2026

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Versions prior to 4.6.0 contain a BGP OPEN capability parsing issue where several concrete capability decoders may parse data from the full remaining capability buffer instead of the slice bounded by the declared capability length, CapLen. A malformed BGP OPEN message can cause bytes from a following capability to be interpreted as part of the current capability. The most security-relevant case is the 4-octet AS capability, where a capability with CapLen == 0 may cause the parser to read bytes from the following capability as the 4-octet AS value. This parsed value may later affect peer AS validation during BGP session establishment. Version 4.6.0 patches the issue.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS Score: 5.9

Product Status

Vendor osrg
Product gobgp
Versions
  • Version < 4.6.0 is affected

References

Problem Types

  • CWE-125: Out-of-bounds Read CWE