Cyber Posture

CVE-2026-41642

HighPublic PoC

Published: 07 May 2026

Published
07 May 2026
Modified
07 May 2026
KEV Added
Patch
CVSS Score 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.0013 32.8th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2026-41642 is a high-severity NULL Pointer Dereference (CWE-476) vulnerability in Osrg Gobgp. Its CVSS base score is 7.5 (High).

Operationally, ranked at the 32.8th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

NVD Description

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP due to a nil pointer dereference. When a malformed BGP UPDATE message…

more

contains an unrecognized Path Attribute marked as "Well-known," the daemon fails to interrupt the message handling flow. This results in an illegal memory access and a full process crash (panic). This issue has been patched in version 4.4.0.

Deeper analysisAI

Automated synthesis unavailable for this CVE.

Details

CWE(s)

Affected Products

osrg
gobgp
4.3.0

CVEs Like This One

CVE-2026-41643Same product: Osrg Gobgp
CVE-2026-7736Same product: Osrg Gobgp
CVE-2026-30405Same product: Osrg Gobgp
CVE-2026-7735Same product: Osrg Gobgp
CVE-2026-4652Shared CWE-476
CVE-2024-46922Shared CWE-476
CVE-2026-33282Shared CWE-476
CVE-2025-0430Shared CWE-476
CVE-2026-31256Shared CWE-476
CVE-2025-69649Shared CWE-476

References