CVE-2026-5123
Severity CVSS v4.0:
MEDIUM
Type:
CWE-189
Numeric Errors
Publication date:
30/03/2026
Last modified:
06/04/2026
Description
A weakness has been identified in osrg GoBGP up to 4.3.0. This impacts the function DecodeFromBytes of the file pkg/packet/bgp/bgp.go. Executing a manipulation of the argument data[1] can lead to off-by-one. The attack may be launched remotely. Attacks of this nature are highly complex. The exploitability is said to be difficult. This patch is called 67c059413470df64bc20801c46f64058e88f800f. A patch should be applied to remediate this issue.
Impact
Base Score 4.0
6.30
Severity 4.0
MEDIUM
Base Score 3.x
3.70
Severity 3.x
LOW
Base Score 2.0
2.60
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:osrg:gobgp:*:*:*:*:*:*:*:* | 4.4.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



