216.73.216.197

CVE-2026-7737

· Published 04/05/2026 07:16 · Modified 04/05/2026 07:16

Labels: CVE-2026-7737 2026-05-04CVE-2026-7737CWE-119[email protected]

Essential information

Published
04/05/2026 07:16
Modified
04/05/2026 07:16
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by this issue is the function BMPPeerUpNotification.ParseBody/BMPStatisticsReport.ParseBody of the file pkg/packet/bmp/bmp.go of the component BMP Parser. The manipulation leads to out-of-bounds read. The attack can be initiated remotely. Upgrading to version 4.4.0 can resolve this issue. The identifier of the patch is bc77597d42335c78464bc8e15a471d887bbdf260. Upgrading the affected component is recommended.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
osrg / gobgp cpe:2.3:a:osrg:gobgp:<4.4.0:*:*:*:*:*:*:*

References