CVE-2026-7734Disclosure(osrg / gobgp)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in osrg GoBGP up to 4.3.0. This impacts the function SRv6L3ServiceAttribute.DecodeFromBytes of the file pkg/packet/bgp/prefix_sid.go of the component SRv6 L3 Service. Such manipulation of the argument data leads to denial of service. The attack may be performed from remote. Upgrading to version 4.4.0 will fix this issue. The name of the patch is f9f7b55ec258e514be0264871fa645a2c3edad11. You should upgrade the affected component.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-404

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gobgp

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
gobgp

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-04: 3Technical Details · 2026-05-04: 205-04
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7734 A vulnerability has been found in osrg GoBGP up to 4.3.0. This impacts the function SRv6L3ServiceAttribute.DecodeFromBytes of the file pkg/packet/bgp/prefix_sid.go of t… https://www.cve.org/CVERecord?id=CVE-2026-7734 ----- Traducción: CVE-2026-7734 Se … http://infoflow.cloud`

    Post summary

    The post alerts on CVE-2026-7734 in osrg GoBGP, outlining the affected function, file, and version, with no PoC or exploit details provided.

    0000039
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7734 A vulnerability has been found in osrg GoBGP up to 4.3.0. This impacts the function SRv6L3ServiceAttribute.DecodeFromBytes of the file pkg/packet/bgp/prefix_sid.go of t… https://www.cve.org/CVERecord?id=CVE-2026-7734

    Post summary

    CVE-2026-7734 has been identified in osrg GoBGP up to version 4.3.0, impacting the SRv6L3ServiceAttribute.DecodeFromBytes function, but no exploitation or patch information is disclosed.

    00000188
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7734 Denial of Service in osrg GoBGP SRv6 L3 Service Up to 4.3.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7734

    Post summary

    The text announces CVE-2026-7734, identifying a DoS vulnerability in osrg GoBGP SRv6 L3 Service up to version 4.3.0, but provides no details on exploitation, PoC, patch, or active attacks.

    0000055
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apposrggobgp---

Explore more