CVE-2026-37457Disclosure(frrouting / frrouting)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • frrouting

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-05-01); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
frrouting

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-01: 2Mentions · 2026-05-29: 1Mentions · 2026-06-03: 1Technical Details · 2026-05-01: 2Technical Details · 2026-05-29: 1Technical Details · 2026-06-03: 105-0105-2906-03
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-012
Disclosure2
2026-05-291
Disclosure1
2026-06-031
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-37457 An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to… https://www.cve.org/CVERecord?id=CVE-2026-37457

    Post summary

    The article announces CVE-2026-37457, detailing an off-by-one out-of-bounds write in FRRouting's bgp_flowspec_op_decode(), but offers no PoC, exploitation or patch information.

    00020221
    57.7K followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🪟 Off-by-one in FRRouting’s FlowSpec decoder (CVE-2026-37457) = “here, have a DoS” via a crafted packet. Even if it’s not Windows, your network still bleeds when Linux edge boxes do. #Windows #Microsoft #Security #Networking https://windowsforum.com/threads/cve-2026-37457-frrouting-bgp-flowspec-off-by-one-dos-and-why-windows-teams-care.422009/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #NetworkSecurity #Cve202637457 https://t.co/dtHmplSvUF

    Post summary

    The article highlights CVE‑2026‑37457 as an off‑by‑one bug in FRRouting’s FlowSpec decoder that can cause a denial‑of‑service when a crafted packet is processed, affecting Linux edge boxes and potentially impacting network operations.

    0000043
    1.1K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 FRRouting (FRR), Out-of-bounds Write, #CVE-2026-37457 (Critical) -DC-May2026-44 https://dailycve.com/frrouting-frr-out-of-bounds-write-cve-2026-37457-critical-dc-may2026-44/

    Post summary

    The post announces the discovery of a new critical out-of-bounds write vulnerability (CVE-2026-37457) affecting FRRouting, with no evidence of PoC, exploit, or active exploitation.

    0000048
    207 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-37457 An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to… https://www.cve.org/CVERecord?id=CVE-2026-37457 ----- Traducción: CVE-2026-37457 Una… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-37457, describing it as an off‑by‑one out‑of‑bounds write in FRRouting’s bgp_flowspec_op_decode function and linking to the CVE record for details.

    0000031
    75 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfrroutingfrrouting10.0--

Explore more