CVE-2026-41643: high-severity vulnerability in osrg gobgp
GoBGP: Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 0.6%
exploitation probability
0.6%top 53% of all CVEs
observed exploitation
nono source reports it
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP where a malformed BGP UPDATE message can trigger a runtime error: index out of range panic. This occurs during the processing of 4-byte AS attributes when the message structure causes an internal slice index shift that is not properly handled. This issue has been patched in version 4.3.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
osrg · gobgpRelated CVEs — osrg gobgp
In the same product, most dangerous first.
CVE-2026-42285HIGHGoBGP: Panic in AdjRib.Update via malformed BGP Update message (Nil Pointer Dereference)EPSS 0.6%CVE-2026-41642HIGHGoBGP: Remote Denial of Service (Panic) via Malformed Well-known Path AttributeEPSS 0.6%CVE-2026-49838MEDIUMGoBGP confederation validation panics on empty AS_PATH attributeEPSS 0.4%CVE-2026-49837MEDIUMGoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundariesEPSS 0.3%