PatchDayAlert
Daily Digest · 2 min read · 5 CVEs · Issue 10 By PatchDayAlert

GoBGP double-tap: two 7.3 parser bugs that can kill your BGP sessions

Two unauthenticated crashes in GoBGP's MRT and AIGP parsers, plus unpatched auth bypasses in MindsDB and yudao-cloud with public exploits already circulating. Prefect's WebSocket endpoint is wide open too.

Patch now
2
Within 24h
1
This week
2
Exploited
0
GoBGPOsrgLinuxPrefectPrefectHQCloudMindsDBYudao CloudRuoyi Vue Pro

Calm Monday, nothing on fire, but a few things worth your attention. Two GoBGP bugs (CVE-2026-7736, CVE-2026-7735) let unauthenticated peers crash your BGP daemon via malformed MRT or AIGP attributes. And if you run Prefect, MindsDB, or yudao-cloud: public exploits are already circulating for all three, with no vendor patches in sight for the last two.


Today's CVEs

Sorted by urgency

02

CVE-2026-7735

NVD
7.3
CVSS
Patch this week HIGH
GoBGPOsrgLinux

An attacker can remotely send a crafted AIGP (Accumulated IGP) BGP attribute that triggers a buffer overflow in GoBGP's packet parser. This could crash the daemon or potentially allow code execution. No authentication is needed, so any peer, or anything spoofing a peer, could fire this off.

Affected estate
Network engineers running GoBGP 4.3.0 or earlier
How to check
Run `gobgpd --version` or inspect your Go module dependency for github.com/osrg/gobgp version.
Included because
unauthenticated; remotely exploitable; buffer overflow; CVSS 7.3
Why it matters
A buffer overflow in the AIGP attribute parser can be triggered by a remote peer, risking daemon crash or worse.

Evidence trail

03

CVE-2026-7723

NVD
7.3
CVSS
Patch within 24h HIGH
PrefectPrefectHQLinuxCloud

Prefect's WebSocket endpoint at /api/events/in has no authentication. An attacker can connect remotely and inject events without credentials. A public exploit is already available, so expect scanning for this soon if it hasn't started already.

Affected estate
Teams running self-hosted PrefectHQ Prefect 3.6.13 or earlier with the API exposed to a network
How to check
Run `prefect version` on your Prefect server host, or check your container image tag. Confirm whether /api/events/in is network-accessible.
Included because
unauthenticated; remotely exploitable; public exploit available; CVSS 7.3
Action
Upgrade Prefect to version 3.6.14. If you can't upgrade immediately, restrict network access to the /api/events/in WebSocket endpoint.
Why it matters
Missing authentication on an event ingestion endpoint lets anyone inject arbitrary events into your workflow orchestration platform.

Evidence trail

04

CVE-2026-7711

NVD
7.3
CVSS
Patch now HIGH
MindsDBLinuxCloud

MindsDB's BYOM (Bring Your Own Model) engine handler lets a remote attacker upload arbitrary files through the proc_wrapper.py exec function with no restrictions. A public exploit exists, and the vendor has not responded to disclosure. There is no patch available right now.

Affected estate
Anyone running MindsDB version 26.01 or earlier, especially instances exposed to the network
How to check
Check your MindsDB version in the admin console or via `pip show mindsdb`. Confirm whether the BYOM handler is active in your configuration.
Included because
unauthenticated; remotely exploitable; unrestricted upload; public exploit available; no vendor patch; CVSS 7.3
Action
Restrict all network access to MindsDB. Disable the BYOM engine handler if not in use. Watch for a vendor patch.
Why it matters
Unrestricted file upload via a remote endpoint can lead to full system compromise. No patch exists and a public exploit is circulating.

Evidence trail

05

CVE-2026-7710

NVD
7.3
CVSS
Patch now HIGH
Yudao CloudRuoyi Vue ProLinuxCloud

The JWT authentication filter in yudao-cloud (Ruoyi-Vue-Pro) can be bypassed by manipulating the mock-token parameter. An attacker can remotely authenticate as any user without valid credentials. A public exploit is available, and the vendor has not responded to disclosure. No patch exists.

Affected estate
Anyone running YunaiV yudao-cloud (Ruoyi-Vue-Pro) version 3.8.0 or earlier
How to check
Check your yudao-cloud version in your deployment configuration or pom.xml. Search your codebase for JwtAuthenticationTokenFilter.java and the mock-token parameter.
Included because
unauthenticated; remotely exploitable; authentication bypass; public exploit available; no vendor patch; CVSS 7.3
Action
Remove the application from public-facing networks. Disable or strip the mock-token parameter handling from JwtAuthenticationTokenFilter.java.
Why it matters
Full authentication bypass lets any remote attacker impersonate users, including admins. A public exploit makes this trivially weaponizable.

Evidence trail


One email, every Wednesday morning.

Subscribe