MEDIUM
osrg
CVE published 2026-09-10
CVE-2026-49838
A denial-of-service vulnerability exists in GoBGP, an open-source Border Gateway Protocol (BGP) implementation in the Go Programming Language. The issue arises from the acceptance of a zero-length AS_PATH during UPDATE decoding, which later causes a panic when validating the attribute for a confederation eBGP peer. This vulnerability is patched in version 4.7.0.