CVE-2026-5122

A security flaw has been discovered in osrg GoBGP up to 4.3.0. This affects the function DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component BGP OPEN Message Handler. Performing a manipulation of the argument domainNameLen results in improper access controls. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is reported as difficult. The patch is named 2b09db390a3d455808363c53e409afe6b1b86d2d. It is suggested to install a patch to address this issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:osrg:gobgp:*:*:*:*:*:*:*:*

History

08 Apr 2026, 16:07

Type Values Removed Values Added
CPE cpe:2.3:a:osrg:gobgp:*:*:*:*:*:*:*:*
References () https://github.com/osrg/gobgp/ - () https://github.com/osrg/gobgp/ - Product
References () https://github.com/osrg/gobgp/commit/2b09db390a3d455808363c53e409afe6b1b86d2d - () https://github.com/osrg/gobgp/commit/2b09db390a3d455808363c53e409afe6b1b86d2d - Patch
References () https://github.com/osrg/gobgp/pull/3343 - () https://github.com/osrg/gobgp/pull/3343 - Issue Tracking
References () https://vuldb.com/submit/780124 - () https://vuldb.com/submit/780124 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/354154 - () https://vuldb.com/vuln/354154 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/354154/cti - () https://vuldb.com/vuln/354154/cti - Permissions Required, VDB Entry
First Time Osrg gobgp
Osrg

01 Apr 2026, 14:24

Type Values Removed Values Added
Summary
  • (es) Una falla de seguridad ha sido descubierta en osrg GoBGP hasta la versión 4.3.0. Esto afecta a la función DecodeFromBytes del archivo pkg/packet/bgp/bgp.go del componente Gestor de Mensajes BGP OPEN. Realizar una manipulación del argumento domainNameLen resulta en controles de acceso inadecuados. El ataque puede ser iniciado de forma remota. Se necesita un alto grado de complejidad para el ataque. La explotabilidad se reporta como difícil. El parche se llama 2b09db390a3d455808363c53e409afe6b1b86d2d. Se sugiere instalar un parche para abordar este problema.

30 Mar 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-30 15:16

Updated : 2026-04-08 16:07


NVD link : CVE-2026-5122

Mitre link : CVE-2026-5122

CVE.ORG link : CVE-2026-5122


JSON object : View

Products Affected

osrg

  • gobgp
CWE
CWE-266

Incorrect Privilege Assignment

CWE-284

Improper Access Control