osrg
- Products in analyzed data
- 1
- Catalog vulnerabilities
- 19
Severity across 13 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 13 analyzed records
A short verification protects source data and prevents automated AI requests.
The GCVE catalog currently lists 19 vulnerability records associated with osrg.
Among the 13 records analyzed by CyStack, 3 are High or Critical and 0 appear in the CISA KEV catalog for priority remediation.
The list below is based on vulnerabilities that have been viewed and analyzed; it does not represent the complete global vulnerability corpus. Use the product filter to narrow the scope.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan
| CVE | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-49838GoBGP confederation validation panics on empty AS_PATH attribute | Exploitation statusNot confirmed | FixNot confirmed | Affected productGoBGP | Published09/10/2026 | SeverityMedium |
CVE-2026-49837GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries | Exploitation statusNot confirmed | FixNot confirmed | Affected productGoBGP | Published09/10/2026 | SeverityMedium |
CVE-2026-41643GoBGP: Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE | Exploitation statusPublic exploit | FixYes | Affected productGoBGP | Published05/07/2026 | SeverityHigh |
CVE-2026-42285GoBGP: Panic in AdjRib.Update via malformed BGP Update message (Nil Pointer Dereference) | Exploitation statusPublic exploit | FixYes | Affected productGoBGP | Published05/07/2026 | SeverityHigh |
CVE-2026-41642GoBGP: Remote Denial of Service (Panic) via Malformed Well-known Path Attribute | Exploitation statusPublic exploit | FixYes | Affected productGoBGP | Published05/07/2026 | SeverityHigh |
CVE-2026-7737osrg GoBGP BMP Parser bmp.go BMPStatisticsReport.ParseBody out-of-bounds | Exploitation statusNot known exploited | FixYes | Affected productGoBGP | Published05/04/2026 | SeverityMedium |
CVE-2026-7736osrg GoBGP mrt.go parseRibEntry integer underflow | Exploitation statusNot known exploited | FixYes | Affected productGoBGP | Published05/04/2026 | SeverityMedium |
CVE-2026-7735osrg GoBGP AIGP Attribute bgp.go PathAttributeAigp.DecodeFromBytes buffer overflow | Exploitation statusNot known exploited | FixYes | Affected productGoBGP | Published05/04/2026 | SeverityMedium |
CVE-2026-7734osrg GoBGP SRv6 L3 Service prefix_sid.go SRv6L3ServiceAttribute.DecodeFromBytes denial of service | Exploitation statusNot known exploited | FixYes | Affected productGoBGP | Published05/04/2026 | SeverityMedium |
CVE-2026-37461CVE-2026-37461 | Exploitation statusNot known exploited | FixNot confirmed | Affected productNot confirmed | Published05/04/2026 | SeverityHigh |
CVE-2026-5124osrg GoBGP BGP Header bgp.go BGPHeader.DecodeFromBytes access control | Exploitation statusNot known exploited | FixYes | Affected productGoBGP | Published03/30/2026 | SeverityMedium |
CVE-2026-5123osrg GoBGP bgp.go DecodeFromBytes off-by-one | Exploitation statusNot known exploited | FixYes | Affected productGoBGP | Published03/30/2026 | SeverityMedium |
CVE-2026-5122osrg GoBGP BGP OPEN Message bgp.go DecodeFromBytes access control | Exploitation statusNot known exploited | FixYes | Affected productGoBGP | Published03/30/2026 | SeverityMedium |
CVE-2026-30405CVE-2026-30405 | Exploitation statusPublic exploit | FixNot confirmed | Affected productNot confirmed | Published03/16/2026 | SeverityHigh |
CVE-2025-7464osrg GoBGP rtr.go SplitRTR out-of-bounds | Exploitation statusNot known exploited | FixYes | Affected productGoBGP | Published07/12/2025 | SeverityMedium |
CVE-2025-43971CVE-2025-43971 | Exploitation statusNot known exploited | FixYes | Affected productGoBGP | Published04/21/2025 | SeverityHigh |
CVE-2025-43972CVE-2025-43972 | Exploitation statusNot known exploited | FixYes | Affected productGoBGP | Published04/21/2025 | SeverityMedium |
CVE-2025-43973CVE-2025-43973 | Exploitation statusNot known exploited | FixYes | Affected productGoBGP | Published04/21/2025 | SeverityMedium |
CVE-2025-43970CVE-2025-43970 | Exploitation statusNot known exploited | FixYes | Affected productGoBGP | Published04/21/2025 | SeverityMedium |