OSRG's vulnerability profile centers on GoBGP, a Border Gateway Protocol implementation used in routing and network infrastructure contexts. The exposure recurs through memory-safety and access-control weakness classes, including off-by-one errors, buffer boundary violations, improper privilege assignment, and input validation gaps that are characteristic of protocol parsers handling untrusted network data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Osrg over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42285HIGH GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.4.0, an unauthenticated remote BGP peer can trigger a fatal panic | May 7, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-41643HIGH GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.3.0, a remote Denial of Service (DoS) vulnerability exists i | May 7, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-41642HIGH GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBG | May 7, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-7736HIGH A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry of the file pkg/packet/mrt/mrt.go. Executing a manipulation c | May 4, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-7734HIGH A vulnerability has been found in osrg GoBGP up to 4.3.0. This impacts the function SRv6L3ServiceAttribute.DecodeFromBytes of the file pkg/packet/bgp/prefix_sid.go of the component | May 4, 2026 | 7.5 | 30 | NO | NO |
CVE-2025-43973CRITICAL An issue was discovered in GoBGP before 3.35.0. pkg/packet/rtr/rtr.go does not verify that the input length corresponds to a situation in which all bytes are available for an RTR m | Apr 21, 2025 | 9.8 | 30 | NO | NO |
CVE-2026-7737HIGH A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by this issue is the function BMPPeerUpNotification.ParseBody/BMPStatisticsReport.ParseBody of the file pkg/packe | May 4, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-7735HIGH A vulnerability was found in osrg GoBGP up to 4.3.0. Affected is the function PathAttributeAigp.DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component AIGP Attribute Pa | May 4, 2026 | 7.3 | 29 | NO | NO |
CVE-2026-37461HIGH An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message. | May 4, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-30405HIGH An issue in GoBGP gobgpd v.4.2.0 allows a remote attacker to cause a denial of service via the NEXT_HOP path attribute | Mar 16, 2026 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Osrg.
Media articles that mention a CVE ID that affects a product developed by Osrg — matched by CVE ID, not by vendor name.