CVE-2026-49838: Osrg Gobgp

Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.7.0, GoBGP accepts a zero-length AS_PATH during UPDATE decoding and later panics while validating that attribute for a confederation eBGP peer. The vulnerable path is in the BGP UPDATE validator: a malformed UPDATE that should be rejected as a malformed AS_PATH instead reaches an unchecked `p.Value[0]` access, allowing a configured confederation eBGP peer to trigger a denial of service. Version 4.7.0 patches the issue.

Affected products

  • Osrg Gobgp: before 4.7.0 (fixed in 4.7.0)

Published 2026-09-10. Last modified 2026-09-16.