PatchSiren

osrg CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM osrg CVE published 2026-09-10

CVE-2026-49838

A denial-of-service vulnerability exists in GoBGP, an open-source Border Gateway Protocol (BGP) implementation in the Go Programming Language. The issue arises from the acceptance of a zero-length AS_PATH during UPDATE decoding, which later causes a panic when validating the attribute for a confederation eBGP peer. This vulnerability is patched in version 4.7.0.