CVE-2026-37462
An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (
CVSS
7.5
Alto
EPSS
0.3%
p20
KEV
—
Exploit Today
6
0-100
Publicado: 3 jun 2026 · Última mod.: 22 jul 2026 · CWE-190
0.3%EPSS · 30 días0.3%
2026-08-082026-09-04
An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-861396.9 MED—
——0In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.1dCVE-2026-861386.9 MED—
——0In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.1dCVE-2026-180784.3 MED—
——0IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow.1dCVE-2026-816666.5 MED19.0%
——6An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check for these messages can be bypassed on 32-bit systems due to an integer overflow in the calculation of the expected message length, allowing a crafted network packet to trigger an out-of-bounds memory access that crashes the Corosync daemon. This results in a denial of service for the affected cluster node. The overflow does not occur on 64-bit systems, where the length calculation is correctly performed in 64-bit arithmetic.2dCVE-2026-854389.8 CRÍ40.1%
——12MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and degree counts from encoded BHV_IPF payloads are used as allocation sizes and loop bounds without validation. Attackers can supply crafted payloads with mismatched dimension values to write attacker-controlled doubles past the end of the IvPBox weight array, causing memory corruption and potential code execution.2dCVE-2026-849655.1 MED0.8%
——0An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale pointer. On builds where sizes are 32 bits, an unauthenticated party able to supply a sufficiently large JSON input to an application that links the library may cause that application to terminate unexpectedly, resulting in denial of service.3d