Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message.
References
Configurations
History
11 May 2026, 19:52
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/FRRouting/frr/commit/8102a8aeceb9f86fdfe1f80cd77080522bab69c8 - Patch | |
| References | () https://github.com/mertsatilmaz/vulnerability-research/blob/main/advisories/CVE-2026-36365.md - Third Party Advisory | |
| CPE | cpe:2.3:a:frrouting:frrouting:*:*:*:*:*:*:*:* | |
| First Time |
Frrouting
Frrouting frrouting |
05 May 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| CWE | CWE-20 |
04 May 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-04 16:16
Updated : 2026-05-11 19:52
NVD link : CVE-2026-37458
Mitre link : CVE-2026-37458
CVE.ORG link : CVE-2026-37458
JSON object : View
Products Affected
frrouting
- frrouting
CWE
CWE-20
Improper Input Validation
