CVE-2026-7736Disclosure(osrg / gobgp)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry of the file pkg/packet/mrt/mrt.go. Executing a manipulation can lead to integer underflow. It is possible to launch the attack remotely. Upgrading to version 4.4.0 addresses this issue. This patch is called 76d911046344a3923cbe573364197aa081944592. It is suggested to upgrade the affected component.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-189CWE-191

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gobgp

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
gobgp

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-04: 3Technical Details · 2026-05-04: 205-04
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7736 Integer Underflow in osrg GoBGP Versions Up to 4.3.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7736

    Post summary

    The post announces CVE‑2026‑7736 as an integer underflow flaw in osrg GoBGP up to version 4.3.0, without reporting exploitation, patches, or proof of concept.

    0000049
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7736 A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry of the file pkg/packet/mrt/mrt.go. Executing a ma… https://www.cve.org/CVERecord?id=CVE-2026-7736 ----- Traducción: CVE-2026-7736 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-7736, indicating a flaw in osrg GoBGP’s parseRibEntry function with basic technical details, but offers no PoC, exploit code, remedial guidance, or evidence of active exploitation.

    0000031
    75 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-7736 A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry of the file pkg/packet/mrt/mrt.go. Executing a ma… https://www.cve.org/CVERecord?id=CVE-2026-7736

    Post summary

    The text announces that CVE-2026-7736 affects GoBGP up to version 4.3.0, noting a problematic function, but provides no additional details on exploitation, patching, or technical nature.

    00000171
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apposrggobgp---

Explore more