Skip to content

[GHSA-4p9m-8gc4-rw2h] GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute - #9717

Open
simondeziel wants to merge 1 commit into
simondeziel/advisory-improvement-9717from
simondeziel-GHSA-4p9m-8gc4-rw2h
Open

simondeziel wants to merge 1 commit into
simondeziel/advisory-improvement-9717from
simondeziel-GHSA-4p9m-8gc4-rw2h

Conversation

@simondeziel

@simondeziel simondeziel commented Sep 22, 2026

Copy link
Copy Markdown

Updates

  • Affected products

Comments
The github.com/osrg/gobgp/v4 module included a fix for GO-2026-4736 in version 4.4.0 onward.

This was also reported here: golang/vulndb#6562

Copilot AI balanced review requested due to automatic review settings September 22, 2026 21:24
@github-actions
github-actions Bot changed the base branch from main to simondeziel/advisory-improvement-9717 September 22, 2026 21:24

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The stale modified timestamp could cause incremental consumers to miss the advisory update.

Review effort: Balanced
Findings: None

What changed in this PR

Updates the GoBGP advisory to reflect the fix released in version 4.4.0.

Changes:

  • Marks 4.4.0 as fixed.
  • Records affected versions through 4.3.0.
File Review
advisories/​github-reviewed/​2026/​03/​GHSA-4p9m-8gc4-rw2h/​GHSA-4p9m-8gc4-rw2h.json The modified timestamp must reflect this update and postdate the v4.4.0 release.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants