VDB
CVE-2026-7735
CVE-2026-7735
PUBLISHED
CVSS 6.9 MEDIUM
Reported by VulDB · Published May 4, 2026
A vulnerability was found in osrg GoBGP up to 4.3.0. Affected is the function PathAttributeAigp.DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component AIGP Attribute Parser. Performing a manipulation results in buffer overflow. It is possible to initiate the attack remotely. Upgrading to version 4.4.0 is able to address this issue. The patch is named 51ad1ada06cb41ce47b7066799981816f50b7ced. The affected component should be upgraded.
EPSS 0.36% · 29.9th percentile
Risk Scores
CVSS 4.0
6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
EPSS Score
0.36%
29.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| osrg | GoBGP | 4.0, 4.1, 4.2 |
| osrg | GoBGP | 4.1, 4.2, 4.3.0 |
Timeline
- May 4, 2026 EPSS Score
- May 4, 2026 CVE Published
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
- May 26, 2026 EPSS Score
- May 27, 2026 EPSS Score
References
- VDB-360910 | osrg GoBGP AIGP Attribute bgp.go PathAttributeAigp.DecodeFromBytes buffer overflow vdb-entrytechnical-description
- VDB-360910 | CTI Indicators (IOB, IOC, IOA) signaturepermissions-required
- Submit #807600 | GoBGP 4.3.0 Improper Input Validation third-party-advisory
- patch
- patch
- product