CVE-2026-5122 | osrg GoBGP up to 4.3.0 BGP OPEN Message pkg/packet/bgp/bgp.go DecodeFromBytes domainNameLen access control (ID 3343 / EUVD-2026-17091)
A vulnerability identified as problematic has been detected in osrg GoBGP up to 4.3.0. This affects the function DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component BGP OPEN Message Handler. Performing a manipulation of the argument domainNameLen results in improper access controls.
This vulnerability was named CVE-2026-5122. The attack may be initiated remotely. There is no available exploit.
It is suggested to install a patch to address this issue.