GHSA-p3w2-64xm-833j · Severity: high · Ecosystem: go — GoBGP has a panic in AdjRib.Update via malformed BGP Update message (Nil Pointer Dereference)
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.4.0, an unauthenticated remote BGP peer can trigger a fatal panic in GoBGP by sending a specially crafted BGP UPDATE message. When the server receives a message with inconsistent attribute lengths, it improperly handles the internal state transition to a "withdraw" action, leading to a nil pointer dereference in the AdjRib.Update function. This causes the entire GoBGP process to crash, resulting in a complete loss of service availability. This issue has been patched in version 4.5.0.
Conclusion & alert: CVE-2026-42285 is rated Exploit Available (58.6/100): CVSS High severity, with low exploitation likelihood (EPSS 0.18%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-13 | 0.12% | 0.18% | +0.05% |
| 2 | 2026-05-08 | — | 0.12% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
GHSA-p3w2-64xm-833j · Severity: high · Ecosystem: go — GoBGP has a panic in AdjRib.Update via malformed BGP Update message (Nil Pointer Dereference)
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2026-42285 unimportant priority: Debian including 1 source packages (gobgp), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2026-42285 |
ubuntu
|
medium | CVE-2026-42285 medium priority: Ubuntu including 1 source packages (gobgp), 7 status rows across 7 suites (bionic, focal, jammy, noble, questing, resolute, upstream): needs-triage 7. | https://ubuntu.com/security/CVE-2026-42285 |
| URL | Tags |
|---|---|
| https://github.com/osrg/gobgp/releases/tag/v4.5.0 | Product Release Notes |
| https://github.com/osrg/gobgp/security/advisories/GHSA-p3w2-64xm-833j | Exploit Vendor Advisory |