mediumCVSS 7.3Vulnerability

CVE-2026-7736

A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry of the file pkg/packet/mrt/mrt.go. Executing a manipulation can lead to integer underflow. It is possible to launch the attack remotely. Upgrading to version 4.4.0 addresses this issue. This patch is called 76d911046344a3923cbe573364197aa081944592. It is suggested to upgrade the affected component.

Properties

summary
GoBGP has an Integer Underflow Issue
severity
medium
epss_score
0.00454
cvss_score
7.3
ghsa_published
2026-05-04T09:31:09Z
source_url
https://github.com/advisories/GHSA-hj4w-qr9j-c4cf
ghsa_updated
2026-05-08T16:58:37Z
ghsa_id
GHSA-hj4w-qr9j-c4cf
cve_id
CVE-2026-7736
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
signal_observed_at
2026-09-11T17:55:57+00:00
is_ghsa_only
false
epss_percentile
0.38779

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]go/github.com/osrg/gobgp/v4

AFFECTS (1)

[Software]go/github.com/osrg/gobgp/v4

HAS_WEAKNESS (1)

[Weakness]Integer Underflow (Wrap or Wraparound)

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph