← Back to CVE Index
CVE-2026-37458
Disclosed 2026-05-04
Description
Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message.
Severity & CVSS Score
6.5
MEDIUM
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
| CWE-ID | Name |
|---|---|
| CWE-20 | Improper Input Validation |
References
| URL | Source |
|---|---|
| https://github.com/FRRouting/frr/commit/8102a8aeceb9f86fdfe1f80cd77080522bab69c8 | GitHub |
| https://github.com/mertsatilmaz/vulnerability-research/blob/main/advisories/CVE-2026-36365.md | GitHub |
Git Fixes
- 8102a8aeceb9f86fdfe1f80cd77080522bab69c8
- 638ee72802b159056234400037421cc5749185be
- 031bdbf5b6832c31048111b56807769236ac85e2
- fed7d6dde1f15ed5dc2c7caedcfcb51112f93a39
Raw Data
- CVE-2026-37458.cve.json — CVE record (JSON)
- CVE-2026-37458.frr.json — FRR-specific data (JSON)