osrg records
17 published records for vendor osrg.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-476 NULL Pointer Dereference2
- CWE-1284 Improper Validation of Specified Quantity in Input2
- CWE-189 Numeric Errors2
- CWE-193 Off-by-one Error2
- CWE-266 Incorrect Privilege Assignment2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2025-43973No exploit | An issue was discovered in GoBGP before 3.35.0.osrg · gobgp · CWE-193 | Critical9.8 | — | 0.6% | Apr 20, 2025 |
30Monitor | CVE-2023-46565No exploit | Buffer Overflow vulnerability in osrg gobgp commit 419c50dfac578daa4d11256904d0dc182f1a9b22 allows a remote attacker to cause a denial of seCWE-120 | High7.5 | — | 0.7% | Apr 29, 2024 |
30Monitor | CVE-2026-37461No exploit | An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) viaosrg · gobgp · CWE-125 | High7.5 | — | 0.6% | May 4, 2026 |
30Monitor | CVE-2026-41643No exploit | GoBGP: Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATEosrg · gobgp · CWE-129 | High7.5 | — | 0.6% | May 7, 2026 |
30Monitor | CVE-2026-41642No exploit | GoBGP: Remote Denial of Service (Panic) via Malformed Well-known Path Attributeosrg · gobgp · CWE-476 | High7.5 | — | 0.6% | May 7, 2026 |
30Monitor | CVE-2026-42285No exploit | GoBGP: Panic in AdjRib.Update via malformed BGP Update message (Nil Pointer Dereference)osrg · gobgp · CWE-476 | High7.5 | — | 0.6% | May 7, 2026 |
30Monitor | CVE-2025-43972No exploit | An issue was discovered in GoBGP before 3.35.0.osrg · gobgp · CWE-1284 | High7.5 | — | 0.6% | Apr 20, 2025 |
30Monitor | CVE-2026-30405No exploit | An issue in GoBGP gobgpd v.4.2.0 allows a remote attacker to cause a denial of service via the NEXT_HOP path attributeosrg · gobgp · CWE-400 | High7.5 | — | 0.5% | Mar 16, 2026 |
30Monitor | CVE-2025-43971No exploit | An issue was discovered in GoBGP before 3.35.0.osrg · gobgp · CWE-193 | High7.5 | — | 0.5% | Apr 20, 2025 |
27Monitor | CVE-2026-7737No exploit | osrg GoBGP BMP Parser bmp.go BMPStatisticsReport.ParseBody out-of-boundsosrg · gobgp · CWE-119 | Medium6.9 | — | 0.9% | May 4, 2026 |
27Monitor | CVE-2026-7734No exploit | osrg GoBGP SRv6 L3 Service prefix_sid.go SRv6L3ServiceAttribute.DecodeFromBytes denial of serviceosrg · gobgp · CWE-404 | Medium6.9 | — | 0.9% | May 4, 2026 |
27Monitor | CVE-2026-7736No exploit | osrg GoBGP mrt.go parseRibEntry integer underflowosrg · gobgp · CWE-189 | Medium6.9 | — | 0.6% | May 4, 2026 |
27Monitor | CVE-2026-7735No exploit | osrg GoBGP AIGP Attribute bgp.go PathAttributeAigp.DecodeFromBytes buffer overflowosrg · gobgp · CWE-119 | Medium6.9 | — | 0.6% | May 4, 2026 |
25Monitor | CVE-2026-5123No exploit | osrg GoBGP bgp.go DecodeFromBytes off-by-oneosrg · gobgp · CWE-189 | Medium6.3 | — | 0.7% | Mar 30, 2026 |
25Monitor | CVE-2026-5124No exploit | osrg GoBGP BGP Header bgp.go BGPHeader.DecodeFromBytes access controlosrg · gobgp · CWE-266 | Medium6.3 | — | 0.5% | Mar 30, 2026 |
25Monitor | CVE-2026-5122No exploit | osrg GoBGP BGP OPEN Message bgp.go DecodeFromBytes access controlosrg · gobgp · CWE-266 | Medium6.3 | — | 0.5% | Mar 30, 2026 |
21Monitor | CVE-2025-43970No exploit | An issue was discovered in GoBGP before 3.35.0.osrg · gobgp · CWE-1284 | Medium5.3 | — | 0.4% | Apr 20, 2025 |
- CVE-2025-4397339Monitor
An issue was discovered in GoBGP before 3.35.0.
CriticalCVSS 9.8No exploitEPSS 1%osrg · gobgpApr 20, 2025
- CVE-2023-4656530Monitor
Buffer Overflow vulnerability in osrg gobgp commit 419c50dfac578daa4d11256904d0dc182f1a9b22 allows a remote attacker to cause a denial of se
HighCVSS 7.5No exploitEPSS 1%Apr 29, 2024
- CVE-2026-3746130Monitor
An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via
HighCVSS 7.5No exploitEPSS 1%osrg · gobgpMay 4, 2026
- CVE-2026-4164330Monitor
GoBGP: Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE
HighCVSS 7.5No exploitEPSS 1%osrg · gobgpMay 7, 2026
- CVE-2026-4164230Monitor
GoBGP: Remote Denial of Service (Panic) via Malformed Well-known Path Attribute
HighCVSS 7.5No exploitEPSS 1%osrg · gobgpMay 7, 2026
- CVE-2026-4228530Monitor
GoBGP: Panic in AdjRib.Update via malformed BGP Update message (Nil Pointer Dereference)
HighCVSS 7.5No exploitEPSS 1%osrg · gobgpMay 7, 2026
- CVE-2025-4397230Monitor
An issue was discovered in GoBGP before 3.35.0.
HighCVSS 7.5No exploitEPSS 1%osrg · gobgpApr 20, 2025
- CVE-2026-3040530Monitor
An issue in GoBGP gobgpd v.4.2.0 allows a remote attacker to cause a denial of service via the NEXT_HOP path attribute
HighCVSS 7.5No exploitEPSS 1%osrg · gobgpMar 16, 2026
- CVE-2025-4397130Monitor
An issue was discovered in GoBGP before 3.35.0.
HighCVSS 7.5No exploitEPSS 1%osrg · gobgpApr 20, 2025
- CVE-2026-773727Monitor
osrg GoBGP BMP Parser bmp.go BMPStatisticsReport.ParseBody out-of-bounds
MediumCVSS 6.9No exploitEPSS 1%osrg · gobgpMay 4, 2026
- CVE-2026-773427Monitor
osrg GoBGP SRv6 L3 Service prefix_sid.go SRv6L3ServiceAttribute.DecodeFromBytes denial of service
MediumCVSS 6.9No exploitEPSS 1%osrg · gobgpMay 4, 2026
- CVE-2026-773627Monitor
osrg GoBGP mrt.go parseRibEntry integer underflow
MediumCVSS 6.9No exploitEPSS 1%osrg · gobgpMay 4, 2026
- CVE-2026-773527Monitor
osrg GoBGP AIGP Attribute bgp.go PathAttributeAigp.DecodeFromBytes buffer overflow
MediumCVSS 6.9No exploitEPSS 1%osrg · gobgpMay 4, 2026
- CVE-2026-512325Monitor
osrg GoBGP bgp.go DecodeFromBytes off-by-one
MediumCVSS 6.3No exploitEPSS 1%osrg · gobgpMar 30, 2026
- CVE-2026-512425Monitor
osrg GoBGP BGP Header bgp.go BGPHeader.DecodeFromBytes access control
MediumCVSS 6.3No exploitEPSS 0%osrg · gobgpMar 30, 2026
- CVE-2026-512225Monitor
osrg GoBGP BGP OPEN Message bgp.go DecodeFromBytes access control
MediumCVSS 6.3No exploitEPSS 0%osrg · gobgpMar 30, 2026
- CVE-2025-4397021Monitor
An issue was discovered in GoBGP before 3.35.0.
MediumCVSS 5.3No exploitEPSS 0%osrg · gobgpApr 20, 2025