Report: CVE-2026-5122 - osrg GoBGP BGP OPEN Message bgp.go DecodeFromBytes access control - Complete Guide

Report: CVE-2026-5122 - osrg GoBGP BGP OPEN Message bgp.go DecodeFromBytes access control - Complete Guide

CVE ID :CVE-2026-5122 Published : March 30, 2026, 2:15 p.m. | 1 hour, 9 minutes ago Description :A security flaw has been discovered in osrg GoBGP up to 4.3.0. This affects the function DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component BGP OPEN Message Handler. Performing a manipulation of the argument domainNameLen results in improper access controls. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is reported as difficult. The patch is named 2b09db390a3d455808363c53e409afe6b1b86d2d. It is suggested to install a patch to address this issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
March 30, 2026