CVE-2025-43971: GoBGP panics due to a zero value for softwareVersionLen
An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-43971 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →