Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 An integer underflow vulnerability exists in the BGPUpdate.DecodeFromBytes function of gobgp version 4.3.0. This flaw allows an attacker to cause a Denial of Service (DoS) by sending a specially crafted BGP UPDATE message. The vulnerability has a high severity rating with a CVSS score of 7.5. No patch or official remediation has been indicated yet. Join the discussion | CVE Database V5 | 06/03/2026, 00:00:00 UTC Added: 06/03/2026, 15:48:54 UTC |
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP where a malformed BGP UPDATE message can trigger a runtime error: index out of range panic. This occurs during the processing of 4-byte AS attributes when the message structure causes an internal slice index shift that is not properly handled. This issue has been patched in version 4.3.0. Join the discussion | CVE Database V5 | 05/07/2026, 11:53:23 UTC Added: 05/07/2026, 12:22:14 UTC |
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.4.0, an unauthenticated remote BGP peer can trigger a fatal panic in GoBGP by sending a specially crafted BGP UPDATE message. When the server receives a message with inconsistent attribute lengths, it improperly handles the internal state transition to a "withdraw" action, leading to a nil pointer dereference in the AdjRib.Update function. This causes the entire GoBGP process to crash, resulting in a complete loss of service availability. This issue has been patched in version 4.5.0. Join the discussion | CVE Database V5 | 05/07/2026, 11:53:14 UTC Added: 05/07/2026, 12:22:14 UTC |
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP due to a nil pointer dereference. When a malformed BGP UPDATE message contains an unrecognized Path Attribute marked as "Well-known," the daemon fails to interrupt the message handling flow. This results in an illegal memory access and a full process crash (panic). This issue has been patched in version 4.4.0. Join the discussion | CVE Database V5 | 05/07/2026, 11:50:41 UTC Added: 05/07/2026, 12:22:14 UTC |
0 A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by this issue is the function BMPPeerUpNotification.ParseBody/BMPStatisticsReport.ParseBody of the file pkg/packet/bmp/bmp.go of the component BMP Parser. The manipulation leads to out-of-bounds read. The attack can be initiated remotely. Upgrading to version 4.4.0 can resolve this issue. The identifier of the patch is bc77597d42335c78464bc8e15a471d887bbdf260. Upgrading the affected component is recommended. Join the discussion | CVE Database V5 | 05/04/2026, 05:45:12 UTC Added: 05/04/2026, 06:36:24 UTC |
0 A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry of the file pkg/packet/mrt/mrt.go. Executing a manipulation can lead to integer underflow. It is possible to launch the attack remotely. Upgrading to version 4.4.0 addresses this issue. This patch is called 76d911046344a3923cbe573364197aa081944592. It is suggested to upgrade the affected component. Join the discussion | CVE Database V5 | 05/04/2026, 05:30:16 UTC Added: 05/04/2026, 06:36:24 UTC |
0 A vulnerability was found in osrg GoBGP up to 4.3.0. Affected is the function PathAttributeAigp.DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component AIGP Attribute Parser. Performing a manipulation results in buffer overflow. It is possible to initiate the attack remotely. Upgrading to version 4.4.0 is able to address this issue. The patch is named 51ad1ada06cb41ce47b7066799981816f50b7ced. The affected component should be upgraded. Join the discussion | CVE Database V5 | 05/04/2026, 05:15:11 UTC Added: 05/04/2026, 05:36:23 UTC |
0 A vulnerability has been found in osrg GoBGP up to 4.3.0. This impacts the function SRv6L3ServiceAttribute.DecodeFromBytes of the file pkg/packet/bgp/prefix_sid.go of the component SRv6 L3 Service. Such manipulation of the argument data leads to denial of service. The attack may be performed from remote. Upgrading to version 4.4.0 will fix this issue. The name of the patch is f9f7b55ec258e514be0264871fa645a2c3edad11. You should upgrade the affected component. Join the discussion | CVE Database V5 | 05/04/2026, 05:00:16 UTC Added: 05/04/2026, 05:36:23 UTC |
0 CVE-2026-37461 is a high-severity vulnerability in gobgp v4.3.0 involving an out-of-bounds read in the ParseIP6Extended function. This flaw can be triggered by an attacker supplying a crafted BGP UPDATE message, resulting in a Denial of Service (DoS) condition. The vulnerability does not impact confidentiality or integrity but causes service disruption. No official patch or remediation guidance is currently available, and no known exploits have been reported in the wild. The vulnerability is related to CWE-125 (Out-of-bounds Read). Join the discussion | CVE Database V5 | 05/04/2026, 00:00:00 UTC Added: 05/04/2026, 16:36:24 UTC |
0 A security vulnerability has been detected in osrg GoBGP up to 4.3.0. Affected is the function BGPHeader.DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component BGP Header Handler. The manipulation leads to improper access controls. Remote exploitation of the attack is possible. The attack is considered to have high complexity. The exploitability is told to be difficult. The identifier of the patch is f0f24a2a901cbf159260698211ab15c583ced131. To fix this issue, it is recommended to deploy a patch. Join the discussion | CVE Database V5 | 03/30/2026, 16:15:12 UTC Added: 03/30/2026, 16:38:17 UTC |
Showing 1 to 10 of 14 results