PatchDay Alert
MAY 4, 2026

CVE

CVE-2026-7735

0 field notes · 1 digest CVSS 7.3


Daily digests

An attacker can remotely send a crafted AIGP (Accumulated IGP) BGP attribute that triggers a buffer overflow in GoBGP's packet parser. This could crash the daemon or potentially allow code execution. No authentication is needed, so any peer, or anything spoofing a peer, could fire this off.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.