Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-w88c-9vg8-cmq8 | GoBGP has Improper Restriction of Operations within the Bounds of a Memory Buffer |
Tue, 05 May 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 04 May 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by this issue is the function BMPPeerUpNotification.ParseBody/BMPStatisticsReport.ParseBody of the file pkg/packet/bmp/bmp.go of the component BMP Parser. The manipulation leads to out-of-bounds read. The attack can be initiated remotely. Upgrading to version 4.4.0 can resolve this issue. The identifier of the patch is bc77597d42335c78464bc8e15a471d887bbdf260. Upgrading the affected component is recommended. | |
| Title | osrg GoBGP BMP Parser bmp.go BMPStatisticsReport.ParseBody out-of-bounds | |
| First Time appeared |
Osrg
Osrg gobgp |
|
| Weaknesses | CWE-119 CWE-125 |
|
| CPEs | cpe:2.3:a:osrg:gobgp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Osrg
Osrg gobgp |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-05-05T00:57:22.608Z
Reserved: 2026-05-03T16:16:33.784Z
Link: CVE-2026-7737
Updated: 2026-05-05T00:57:17.912Z
Status : Analyzed
Published: 2026-05-04T07:16:01.700
Modified: 2026-05-06T20:27:58.080
Link: CVE-2026-7737
No data.
OpenCVE Enrichment
Updated: 2026-05-04T07:45:05Z
Github GHSA