CVE-2026-5123

LOW

osrg GoBGP bgp.go DecodeFromBytes off-by-one

Title source: cna
STIX 2.1

Description

A weakness has been identified in osrg GoBGP up to 4.3.0. This impacts the function DecodeFromBytes of the file pkg/packet/bgp/bgp.go. Executing a manipulation of the argument data[1] can lead to off-by-one. The attack may be launched remotely. Attacks of this nature are highly complex. The exploitability is said to be difficult. This patch is called 67c059413470df64bc20801c46f64058e88f800f. A patch should be applied to remediate this issue.

References (6)

Core 6
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-354155 | osrg GoBGP bgp.go DecodeFromBytes off-by-one
https://vuldb.com/vuln/354155
Signature, Permissions Required signature permissions-required
VDB-354155 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/354155/cti
Third Party Advisory third-party-advisory
Submit #780179 | osrg GoBGP 4.3.0 Off-by-one Error
https://vuldb.com/submit/780179
Patch issue-tracking patch
https://github.com/osrg/gobgp/pull/3342

Scores

CVSS v3 3.7
EPSS 0.0041
EPSS Percentile 32.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-189 CWE-193
Status published
Products (5)
osrg/gobgp < 4.4.0
osrg/GoBGP 4.0
osrg/GoBGP 4.1
osrg/GoBGP 4.2
osrg/GoBGP 4.3.0
Published Mar 30, 2026
Tracked Since Mar 30, 2026