High severity7.5NVD Advisory· Published May 1, 2026· Updated May 7, 2026
CVE-2026-37457
CVE-2026-37457
Description
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
1- Patch Tuesday - May 2026Rapid7 Blog · May 13, 2026