CVE-2026-37462
the affected product
An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
- CVSS
- 7.5
- EPSS
- 0.28% 20.1% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.04