What is CVE-2026-54332?
This vulnerability in gopacket's sFlow ExtendedGatewayFlow decoder allows an attacker to trigger unbounded slice allocations using controlled community and AS path member counts, potentially leading to denial of service (DoS). Users of affected Go applications should upgrade to a patched version.
Azərbaycanca: Bu boşluq gopacket-in sFlow ExtendedGatewayFlow deşifrləyicisində zərərverici tərəfindən idarə olunan sayğaclara əsaslanaraq məhdudiyyətsiz yaddaş ayrılmasına səbəb olur, bu da potensial xidmət rəddi (DoS) hücumlarına yol aça bilər. Təsirə məruz qalan versiyalardan istifadə edən Go tətbiqlərini yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
In which decoder of the gopacket library was CVE-2026-54332 discovered?
This vulnerability was discovered in gopacket's sFlow ExtendedGatewayFlow decoder.
What action should be taken for applications affected by CVE-2026-54332?
Affected Go applications should be upgraded to a patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.