An off-by-one out-of-bounds write vulnerability in the bgpflowspecopdecode() function (bgpd/bgpflowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/37xxx/CVE-2026-37457.json",
"cna_assigner": "mitre"
}[
{
"digest": {
"line_hashes": [
"70203518157991788059589249358584491773",
"339493298477160008444121123548945795090",
"220060263767998761351801902403723841861",
"138796088628398828774366363276051391257",
"323869506605232209770712306872727708856",
"240045892448241534760224328400224736540",
"205751541838883250232327288654861921512",
"89670831658012169823176879374640645846",
"299629851774576051021819406685035984563"
],
"threshold": 0.9
},
"id": "CVE-2026-37457-62a14b92",
"signature_version": "v1",
"target": {
"file": "bgpd/bgp_flowspec_util.c"
},
"deprecated": false,
"source": "https://github.com/frrouting/frr/commit/0e6882bc72c0278988a47b2f0f73b7a91099a25c",
"signature_type": "Line"
},
{
"digest": {
"function_hash": "311707315261189954997073606686648123025",
"length": 1995.0
},
"id": "CVE-2026-37457-6b966e94",
"signature_version": "v1",
"target": {
"file": "bgpd/bgp_flowspec_util.c",
"function": "bgp_flowspec_op_decode"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://github.com/frrouting/frr/commit/0e6882bc72c0278988a47b2f0f73b7a91099a25c"
},
{
"digest": {
"function_hash": "223631915427432894996681863711670348562",
"length": 2073.0
},
"id": "CVE-2026-37457-fc0d213c",
"signature_version": "v1",
"target": {
"file": "bgpd/bgp_flowspec_util.c",
"function": "bgp_flowspec_bitmask_decode"
},
"deprecated": false,
"signature_type": "Function",
"source": "https://github.com/frrouting/frr/commit/0e6882bc72c0278988a47b2f0f73b7a91099a25c"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-37457.json"
"2026-05-28T08:52:12Z"