CVE detail
CVE-2026-5123
A weakness has been identified in osrg GoBGP up to 4.3.0. This impacts the function DecodeFromBytes of the file pkg/packet/bgp/bgp.go. Executing a manipulation of the argument data[1] can lead to off-by-one. The attack may be launched remotely. Attacks of this nature are highly complex. The exploitability is said to be difficult. This patch is called 67c059413470df64bc20801c46f64058e88f800f. A patch should be applied to remediate this issue.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- https://vuldb.com/vuln/354155/ctivuldb.com
No excerpt available.
Exploitvuldb.comMar 30, 2026, 4:16 PM - https://vuldb.com/vuln/354155vuldb.com
No excerpt available.
Exploitvuldb.comMar 30, 2026, 4:16 PM - https://vuldb.com/submit/780179vuldb.com
No excerpt available.
Exploitvuldb.comMar 30, 2026, 4:16 PM - https://github.com/osrg/gobgp/pull/3342github.com
No excerpt available.
Exploitgithub.comMar 30, 2026, 4:16 PM No excerpt available.
Exploitgithub.comMar 30, 2026, 4:16 PM- https://github.com/osrg/gobgp/github.com
No excerpt available.
Exploitgithub.comMar 30, 2026, 4:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-2703CVSS 1.9 · Low
A weakness has been identified in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::decode_base64 of the file source/detail/cryptography/base64.cpp of the co…
- CVE-2026-7736CVSS 6.9 · Medium
A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry of the file pkg/packet/mrt/mrt.go. Executing a manipulation…
- CVE-2025-43973CVSS 6.8 · Medium
An issue was discovered in GoBGP before 3.35.0. pkg/packet/rtr/rtr.go does not verify that the input length corresponds to a situation in which all bytes are available for an RTR…
- CVE-2025-43971CVSS 8.6 · High
An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen.
- CVE-2026-14899CVSS 7.5 · High
The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read fr…
- CVE-2026-44687CVSS 3.7 · Low
In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is below an intermediate labed below a DNSSEC signed zone could be shadowed by the in…