Loading
An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by ensuring that there are 12 bytes or 36 bytes (depending on the address family).
Cite this page
CVE-2025-43970. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2025-43970
Use CWE-1284, Osrg vendor hub and Gobgp product page to widen CVE-2025-43970 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-43971, CVE-2026-30405 and CVE-2025-43973 for nearby disclosures in the same product family.