Vulnerabilities in GoBGP
4 resultsVexday analysis
GoBGP apresenta 4 vulnerabilidades catalogadas sem criticidade máxima e nenhuma sob exploração ativa, indicando risco contido. A ausência de divulgações recentes e de ataques em campo sugere que as vulnerabilidades existentes não constituem ameaça imediata. A fraqueza dominante (CWE-1284 - Improper Validation of Specified Quantity in Input) aponta para problemas de validação de entrada, recomendando revisão de controles de bounds checking nas futuras atualizações.
CVE-2025-43973MEDIUMAn issue was discovered in GoBGP before 3.35.0. pkg/packet/rtr/rtr.go does not verify that the input length corresponds to a situation in whEPSS 0.6%CVE-2025-43972MEDIUMAn issue was discovered in GoBGP before 3.35.0. An attacker can cause a crash in the pkg/packet/bgp/bgp.go flowspec parser by sending fewer EPSS 0.5%CVE-2025-43971HIGHAn issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionEPSS 0.5%CVE-2025-43970MEDIUMAn issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by ensuring that thereEPSS 0.4%