Improper Access Control Vulnerability in osrg GoBGP Network Software
CVE-2026-5124
6.3MEDIUM
What is CVE-2026-5124?
A security vulnerability exists in the osrg GoBGP software, specifically in the BGPHeader.DecodeFromBytes function found within the BGP Header Handler component. This flaw permits unauthorized access due to insufficient access controls, enabling potential remote exploitation. Despite the complexity associated with exploiting this vulnerability, it poses a security risk and requires immediate attention. Users of GoBGP versions up to 4.3.0 are advised to apply the latest patch identified in the project's commit history to safeguard their systems.
Affected Version(s)
GoBGP 4.0
GoBGP 4.1
GoBGP 4.2
