CVE-2026-41643

EUVD-2026-28352
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP where a malformed BGP UPDATE message can trigger a runtime error: index out of range panic. This occurs during the processing of 4-byte AS attributes when the message structure causes an internal slice index shift that is not properly handled. This issue has been patched in version 4.3.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 42.55%
Affected Products (NVD)
VendorProductVersion
osrggobgp
𝑥
< 4.3.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gobgp
bookworm
no-dsa
bullseye
postponed
forky
4.7.0-1
fixed
sid
4.7.0-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gobgp
bionic
Fixed 1.29-1ubuntu0.1+esm2
released
focal
Fixed 2.12.0-1ubuntu0.1~esm3
released
jammy
Fixed 2.25.0-3ubuntu0.1+esm4
released
noble
Fixed 3.23.0-1ubuntu0.3+esm4
released
questing
ignored
resolute
Fixed 3.36.0-2ubuntu0.1~esm1
released