CVE-2026-5122 PUBLISHED

osrg GoBGP BGP OPEN Message bgp.go DecodeFromBytes access control

Assigner: VulDB
Reserved: 30.03.2026 Published: 30.03.2026 Updated: 30.03.2026

A security flaw has been discovered in osrg GoBGP up to 4.3.0. This affects the function DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component BGP OPEN Message Handler. Performing a manipulation of the argument domainNameLen results in improper access controls. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is reported as difficult. The patch is named 2b09db390a3d455808363c53e409afe6b1b86d2d. It is suggested to install a patch to address this issue.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X
CVSS Score: 6.3

Product Status

Vendor osrg
Product GoBGP
Versions
  • Version 4.0 is affected
  • Version 4.1 is affected
  • Version 4.2 is affected
  • Version 4.3.0 is affected

Credits

  • rensiru (VulDB User) reporter

References

Problem Types

  • Improper Access Controls CWE
  • Incorrect Privilege Assignment CWE