github.com/osrg/gobgp/v4
BGP implemented in the Go Programming Language
Activity
- Latest release
- 1w ago
- Total releases
- 10
- Cadence
- ~31 days
- Last 12 months
- 10
Reach
- Stars
- 4.1k
Details
- First release
- Nov 03, 2025
| Version | Released | |
|---|---|---|
v4.9.0
minor
1 CVE
CVE-2026-30405
GO-2026-4736
GHSA-4p9m-8gc4-rw2h
Apr 07, 2026
GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute in github.com/osrg/gobgp GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute in github.com/osrg/gobgp References Updated Jun 26, 2026 · Source: OSV.dev |
v4.9.0
minor
Dependencies (29)
+ 21 more |
|
v4.8.0
minor
1 CVE
CVE-2026-30405
GO-2026-4736
GHSA-4p9m-8gc4-rw2h
Apr 07, 2026
GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute in github.com/osrg/gobgp GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute in github.com/osrg/gobgp References Updated Jun 26, 2026 · Source: OSV.dev |
v4.8.0
minor
Dependencies (29)
+ 21 more |
|
v4.7.0
minor
1 CVE
CVE-2026-30405
GO-2026-4736
GHSA-4p9m-8gc4-rw2h
Apr 07, 2026
GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute in github.com/osrg/gobgp GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute in github.com/osrg/gobgp References Updated Jun 26, 2026 · Source: OSV.dev |
v4.7.0
minor
Dependencies (29)
+ 21 more |
|
v4.6.0
minor
2 CVEs
CVE-2026-49838
GO-2026-5954
GHSA-frrj-87jh-2772
Jul 24, 2026
GoBGP confederation validation panics on empty AS_PATH attribute in github.com/osrg/gobgp GoBGP confederation validation panics on empty AS_PATH attribute in github.com/osrg/gobgp Fixed in
4.7.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-30405
GO-2026-4736
GHSA-4p9m-8gc4-rw2h
Apr 07, 2026
GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute in github.com/osrg/gobgp GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute in github.com/osrg/gobgp References Updated Jun 26, 2026 · Source: OSV.dev |
v4.6.0
minor
Dependencies (29)
+ 21 more |
|
v4.5.0
minor
3 CVEs
CVE-2026-49837
GO-2026-5955
GHSA-gjrg-jjr3-56cm
Jul 24, 2026
GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries in github.com/osrg/gobgp GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries in github.com/osrg/gobgp Fixed in
4.6.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-49838
GO-2026-5954
GHSA-frrj-87jh-2772
Jul 24, 2026
GoBGP confederation validation panics on empty AS_PATH attribute in github.com/osrg/gobgp GoBGP confederation validation panics on empty AS_PATH attribute in github.com/osrg/gobgp Fixed in
4.7.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-30405
GO-2026-4736
GHSA-4p9m-8gc4-rw2h
Apr 07, 2026
GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute in github.com/osrg/gobgp GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute in github.com/osrg/gobgp References Updated Jun 26, 2026 · Source: OSV.dev |
v4.5.0
minor
Dependencies (28)
+ 20 more |
|
v4.4.0
minor
4 CVEs
CVE-2026-49837
GO-2026-5955
GHSA-gjrg-jjr3-56cm
Jul 24, 2026
GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries in github.com/osrg/gobgp GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries in github.com/osrg/gobgp Fixed in
4.6.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-49838
GO-2026-5954
GHSA-frrj-87jh-2772
Jul 24, 2026
GoBGP confederation validation panics on empty AS_PATH attribute in github.com/osrg/gobgp GoBGP confederation validation panics on empty AS_PATH attribute in github.com/osrg/gobgp Fixed in
4.7.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-42285
GO-2026-5525
GHSA-p3w2-64xm-833j
Jul 24, 2026
GoBGP has a panic in AdjRib.Update via malformed BGP Update message (Nil Pointer Dereference) in github.com/osrg/gobgp GoBGP has a panic in AdjRib.Update via malformed BGP Update message (Nil Pointer Dereference) in github.com/osrg/gobgp Fixed in
4.5.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-30405
GO-2026-4736
GHSA-4p9m-8gc4-rw2h
Apr 07, 2026
GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute in github.com/osrg/gobgp GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute in github.com/osrg/gobgp References Updated Jun 26, 2026 · Source: OSV.dev |
v4.4.0
minor
Dependencies (28)
+ 20 more |
|
v4.3.0
minor
9 CVEs
CVE-2026-37462
GO-2026-5971
GHSA-pw7p-7fqv-hpj8
Jul 24, 2026
GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes function in github.com/osrg/gobgp GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes function in github.com/osrg/gobgp Fixed in
4.4.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-49837
GO-2026-5955
GHSA-gjrg-jjr3-56cm
Jul 24, 2026
GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries in github.com/osrg/gobgp GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries in github.com/osrg/gobgp Fixed in
4.6.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-49838
GO-2026-5954
GHSA-frrj-87jh-2772
Jul 24, 2026
GoBGP confederation validation panics on empty AS_PATH attribute in github.com/osrg/gobgp GoBGP confederation validation panics on empty AS_PATH attribute in github.com/osrg/gobgp Fixed in
4.7.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-41642
GO-2026-5198
GHSA-7235-89m6-f4px
Jul 24, 2026
GoBGP: Remote Denial of Service (Panic) via Malformed Well-known Path Attribute in github.com/osrg/gobgp GoBGP: Remote Denial of Service (Panic) via Malformed Well-known Path Attribute in github.com/osrg/gobgp Fixed in
4.4.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-37461
GO-2026-5713
GHSA-wmvj-f67g-qg4g
Jul 07, 2026
GoBGP has an out-of-bounds read in the ParseIP6Extended function in github.com/osrg/gobgp GoBGP has an out-of-bounds read in the ParseIP6Extended function in github.com/osrg/gobgp Fixed in
4.4.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7736
GO-2026-5427
GHSA-hj4w-qr9j-c4cf
Jul 07, 2026
GoBGP has an Integer Underflow Issue in github.com/osrg/gobgp GoBGP has an Integer Underflow Issue in github.com/osrg/gobgp Fixed in
4.4.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7734
GO-2026-5665
GHSA-vm3g-8xwv-mxfp
Jul 07, 2026
GoBGP has an Improper Resource Shutdown or Release in github.com/osrg/gobgp GoBGP has an Improper Resource Shutdown or Release in github.com/osrg/gobgp Fixed in
4.4.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7737
GO-2026-5699
GHSA-w88c-9vg8-cmq8
Jul 07, 2026
GoBGP has Improper Restriction of Operations within the Bounds of a Memory Buffer in github.com/osrg/gobgp GoBGP has Improper Restriction of Operations within the Bounds of a Memory Buffer in github.com/osrg/gobgp Fixed in
4.4.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30405
GO-2026-4736
GHSA-4p9m-8gc4-rw2h
Apr 07, 2026
GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute in github.com/osrg/gobgp GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute in github.com/osrg/gobgp References Updated Jun 26, 2026 · Source: OSV.dev |
v4.3.0
minor
Dependencies (27)
+ 19 more |
|
v4.2.0
minor
9 CVEs
CVE-2026-41643
GO-2026-5266
GHSA-8rxh-r2p6-7f2q
Jul 24, 2026
GoBGP: Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE in github.com/osrg/gobgp GoBGP: Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE in github.com/osrg/gobgp Fixed in
4.3.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-37462
GO-2026-5971
GHSA-pw7p-7fqv-hpj8
Jul 24, 2026
GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes function in github.com/osrg/gobgp GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes function in github.com/osrg/gobgp Fixed in
4.4.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-49837
GO-2026-5955
GHSA-gjrg-jjr3-56cm
Jul 24, 2026
GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries in github.com/osrg/gobgp GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries in github.com/osrg/gobgp Fixed in
4.6.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-49838
GO-2026-5954
GHSA-frrj-87jh-2772
Jul 24, 2026
GoBGP confederation validation panics on empty AS_PATH attribute in github.com/osrg/gobgp GoBGP confederation validation panics on empty AS_PATH attribute in github.com/osrg/gobgp Fixed in
4.7.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-37461
GO-2026-5713
GHSA-wmvj-f67g-qg4g
Jul 07, 2026
GoBGP has an out-of-bounds read in the ParseIP6Extended function in github.com/osrg/gobgp GoBGP has an out-of-bounds read in the ParseIP6Extended function in github.com/osrg/gobgp Fixed in
4.4.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7736
GO-2026-5427
GHSA-hj4w-qr9j-c4cf
Jul 07, 2026
GoBGP has an Integer Underflow Issue in github.com/osrg/gobgp GoBGP has an Integer Underflow Issue in github.com/osrg/gobgp Fixed in
4.4.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7734
GO-2026-5665
GHSA-vm3g-8xwv-mxfp
Jul 07, 2026
GoBGP has an Improper Resource Shutdown or Release in github.com/osrg/gobgp GoBGP has an Improper Resource Shutdown or Release in github.com/osrg/gobgp Fixed in
4.4.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7737
GO-2026-5699
GHSA-w88c-9vg8-cmq8
Jul 07, 2026
GoBGP has Improper Restriction of Operations within the Bounds of a Memory Buffer in github.com/osrg/gobgp GoBGP has Improper Restriction of Operations within the Bounds of a Memory Buffer in github.com/osrg/gobgp Fixed in
4.4.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30405
GO-2026-4736
GHSA-4p9m-8gc4-rw2h
Apr 07, 2026
GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute in github.com/osrg/gobgp GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute in github.com/osrg/gobgp References Updated Jun 26, 2026 · Source: OSV.dev |
v4.2.0
minor
Dependencies (27)
+ 19 more |
|
v4.1.0
minor
9 CVEs
CVE-2026-41643
GO-2026-5266
GHSA-8rxh-r2p6-7f2q
Jul 24, 2026
GoBGP: Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE in github.com/osrg/gobgp GoBGP: Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE in github.com/osrg/gobgp Fixed in
4.3.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-37462
GO-2026-5971
GHSA-pw7p-7fqv-hpj8
Jul 24, 2026
GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes function in github.com/osrg/gobgp GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes function in github.com/osrg/gobgp Fixed in
4.4.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-49837
GO-2026-5955
GHSA-gjrg-jjr3-56cm
Jul 24, 2026
GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries in github.com/osrg/gobgp GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries in github.com/osrg/gobgp Fixed in
4.6.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-49838
GO-2026-5954
GHSA-frrj-87jh-2772
Jul 24, 2026
GoBGP confederation validation panics on empty AS_PATH attribute in github.com/osrg/gobgp GoBGP confederation validation panics on empty AS_PATH attribute in github.com/osrg/gobgp Fixed in
4.7.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-37461
GO-2026-5713
GHSA-wmvj-f67g-qg4g
Jul 07, 2026
GoBGP has an out-of-bounds read in the ParseIP6Extended function in github.com/osrg/gobgp GoBGP has an out-of-bounds read in the ParseIP6Extended function in github.com/osrg/gobgp Fixed in
4.4.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7736
GO-2026-5427
GHSA-hj4w-qr9j-c4cf
Jul 07, 2026
GoBGP has an Integer Underflow Issue in github.com/osrg/gobgp GoBGP has an Integer Underflow Issue in github.com/osrg/gobgp Fixed in
4.4.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7734
GO-2026-5665
GHSA-vm3g-8xwv-mxfp
Jul 07, 2026
GoBGP has an Improper Resource Shutdown or Release in github.com/osrg/gobgp GoBGP has an Improper Resource Shutdown or Release in github.com/osrg/gobgp Fixed in
4.4.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7737
GO-2026-5699
GHSA-w88c-9vg8-cmq8
Jul 07, 2026
GoBGP has Improper Restriction of Operations within the Bounds of a Memory Buffer in github.com/osrg/gobgp GoBGP has Improper Restriction of Operations within the Bounds of a Memory Buffer in github.com/osrg/gobgp Fixed in
4.4.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30405
GO-2026-4736
GHSA-4p9m-8gc4-rw2h
Apr 07, 2026
GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute in github.com/osrg/gobgp GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute in github.com/osrg/gobgp References Updated Jun 26, 2026 · Source: OSV.dev |
v4.1.0
minor
Dependencies (27)
+ 19 more |
|
v4.0.0
initial
9 CVEs
CVE-2026-41643
GO-2026-5266
GHSA-8rxh-r2p6-7f2q
Jul 24, 2026
GoBGP: Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE in github.com/osrg/gobgp GoBGP: Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE in github.com/osrg/gobgp Fixed in
4.3.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-37462
GO-2026-5971
GHSA-pw7p-7fqv-hpj8
Jul 24, 2026
GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes function in github.com/osrg/gobgp GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes function in github.com/osrg/gobgp Fixed in
4.4.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-49837
GO-2026-5955
GHSA-gjrg-jjr3-56cm
Jul 24, 2026
GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries in github.com/osrg/gobgp GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries in github.com/osrg/gobgp Fixed in
4.6.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-49838
GO-2026-5954
GHSA-frrj-87jh-2772
Jul 24, 2026
GoBGP confederation validation panics on empty AS_PATH attribute in github.com/osrg/gobgp GoBGP confederation validation panics on empty AS_PATH attribute in github.com/osrg/gobgp Fixed in
4.7.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-37461
GO-2026-5713
GHSA-wmvj-f67g-qg4g
Jul 07, 2026
GoBGP has an out-of-bounds read in the ParseIP6Extended function in github.com/osrg/gobgp GoBGP has an out-of-bounds read in the ParseIP6Extended function in github.com/osrg/gobgp Fixed in
4.4.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7736
GO-2026-5427
GHSA-hj4w-qr9j-c4cf
Jul 07, 2026
GoBGP has an Integer Underflow Issue in github.com/osrg/gobgp GoBGP has an Integer Underflow Issue in github.com/osrg/gobgp Fixed in
4.4.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7734
GO-2026-5665
GHSA-vm3g-8xwv-mxfp
Jul 07, 2026
GoBGP has an Improper Resource Shutdown or Release in github.com/osrg/gobgp GoBGP has an Improper Resource Shutdown or Release in github.com/osrg/gobgp Fixed in
4.4.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7737
GO-2026-5699
GHSA-w88c-9vg8-cmq8
Jul 07, 2026
GoBGP has Improper Restriction of Operations within the Bounds of a Memory Buffer in github.com/osrg/gobgp GoBGP has Improper Restriction of Operations within the Bounds of a Memory Buffer in github.com/osrg/gobgp Fixed in
4.4.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-30405
GO-2026-4736
GHSA-4p9m-8gc4-rw2h
Apr 07, 2026
GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute in github.com/osrg/gobgp GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute in github.com/osrg/gobgp References Updated Jun 26, 2026 · Source: OSV.dev |
v4.0.0
initial
Dependencies (27)
+ 19 more |