CVE-2026-37458: Input Validation
Published May 4, 2026
·Updated
Missing input validation in the MPREACHNLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message.
Affected Software
2 affected components
Frrouting FRRouting>=stable/10.0<=stable/10.6
Frrouting FRRouting>=10.0<=10.6.0
Remediation
Event History
May 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-37458?
CVE-2026-37458 has a medium severity rating of 6.5 according to the CVSS 3.1 metrics.
2
What is CVE-2026-37458 about?
CVE-2026-37458 involves missing input validation in the MP_REACH_NLRI component of FRRouting that can lead to a Denial of Service (DoS) when exploited.
3
Who can exploit CVE-2026-37458?
Authenticated attackers can exploit CVE-2026-37458 by sending a specially crafted UPDATE message.
4
How do I fix CVE-2026-37458?
To fix CVE-2026-37458, apply the available patch provided in the FRRouting repository.
5
What impact does CVE-2026-37458 have on systems?
The impact of CVE-2026-37458 includes the potential for Denial of Service (DoS), affecting system availability.