GHSA-vm3g-8xwv-mxfp

Suggest an improvement
Source
https://github.com/advisories/GHSA-vm3g-8xwv-mxfp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-vm3g-8xwv-mxfp/GHSA-vm3g-8xwv-mxfp.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-vm3g-8xwv-mxfp
Aliases
Published
2026-05-04T06:32:02Z
Modified
2026-07-07T20:41:18Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
GoBGP has an Improper Resource Shutdown or Release
Details

A vulnerability has been found in osrg GoBGP up to 4.3.0. This impacts the function SRv6L3ServiceAttribute.DecodeFromBytes of the file pkg/packet/bgp/prefix_sid.go of the component SRv6 L3 Service. Such manipulation of the argument data leads to denial of service. The attack may be performed from remote. Upgrading to version 4.4.0 will fix this issue. The name of the patch is f9f7b55ec258e514be0264871fa645a2c3edad11. Users should upgrade the affected component.

Database specific
{
    "cwe_ids": [
        "CWE-404"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-05-08T16:51:50Z",
    "nvd_published_at": "2026-05-04T06:16:02Z",
    "severity": "MODERATE"
}
References

Affected packages

Go / github.com/osrg/gobgp/v4

Package

Name
github.com/osrg/gobgp/v4
View open source insights on deps.dev
Purl
pkg:golang/github.com/osrg/gobgp/v4

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.4.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-vm3g-8xwv-mxfp/GHSA-vm3g-8xwv-mxfp.json"