A AegiFlow
MEDIUMCVSS 6.9EPSS 0.4%

CVE-2026-54345

CVE-2026-54345 updated by NVD

Published
2026-07-28
Modified
2026-07-31
EPSS percentile
32%
Sources
github-advisory, nvd

Summary

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtracting a fixed header size from an attacker-controlled AVP Length field, so a vendor-flagged AVP whose Length is smaller than the 12-byte header underflows the unsigned 32-bit value and drives an unbounded allocation of roughly 4 GiB, and two such messages in succession OOM-kill a collector, causing an unauthenticated remote denial of service. This issue is fixed in version 1.6.1.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/gopacket/gopacket1.6.1

Remediation: Upgrade to 1.6.1 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.