Medium severity5.9NVD Advisory· Published Sep 10, 2026
CVE-2026-49838
CVE-2026-49838
Description
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.7.0, GoBGP accepts a zero-length AS_PATH during UPDATE decoding and later panics while validating that attribute for a confederation eBGP peer. The vulnerable path is in the BGP UPDATE validator: a malformed UPDATE that should be rejected as a malformed AS_PATH instead reaches an unchecked p.Value[0] access, allowing a configured confederation eBGP peer to trigger a denial of service. Version 4.7.0 patches the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/osrg/gobgp/v4Go | < 4.7.0 | 4.7.0 |
Affected products
7- osv-coords6 versionspkg:apk/chainguard/kube-vippkg:apk/wolfi/kube-vippkg:apk/wolfi/cilium-clipkg:apk/chainguard/cilium-clipkg:apk/chainguard/kube-vip-fipspkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0
< 1.2.1-r2+ 5 more
- (no CPE)range: < 1.2.1-r2
- (no CPE)range: < 1.2.1-r2
- (no CPE)range: < 0.19.5-r3
- (no CPE)range: < 0.19.5-r3
- (no CPE)range: < 1.2.1-r2
- (no CPE)range: < 0.0.20260727T201416-160000.1.1
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.