StackRadar

CVE-2026-30405

Unscored

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.003
26th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
17
of 17,781 indexed, latest versions
Container images
17
deployed by those charts
Fix available
None
affected packages

GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute in github.com/osrg/gobgp

Carried by container images the latest versions of 17 of 17,781 indexed charts deploy, on 17 images.

Affected packageAffected versionsFixed inImages
github.com/osrg/gobgpgolangv0.0.0-20170802061517-bbd1d99396fe, v0.0.0-20210101133947-496b372f7b8d, v0.0.0-20210801043420-9e48a36ed97cno fix listed6
github.com/osrg/gobgp/v4golangv4.6.1-0.20260630022313-d6dee8360046, v4.8.0no fix listed6
github.com/osrg/gobgp/v3golangv0.0.0-20240802091257-b91614eb13ca, v3.14.0, v3.21.0, v3.37.0no fix listed5
OSV records
GO-2026-4736
Also known as
GHSA-4p9m-8gc4-rw2h

Charts affected

17 by stars
ChartLatestAffected imagesRadar Score
ciliumciliumOfficialVerified publisher1.20.12 of 3See more

cilium cilium 1.20.1

2 of the 3 container images this version deploys carry CVE-2026-30405.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.20.1ae9ea21f7427
github.com/osrg/gobgp/v4@v4.6.1-0.20260630022313-d6dee8360046
no fix listed
quay.io/cilium/operator-generic:v1.20.16c3885fc7b62
github.com/osrg/gobgp/v4@v4.6.1-0.20260630022313-d6dee8360046
no fix listed

Open the chart page →

1,708
kube-vipkube-vip0.11.11 of 1See more

kube-vip kube-vip 0.11.1

1 of the 1 container images this version deploys carry CVE-2026-30405.

Container imageDigestPackageFixed in
ghcr.io/kube-vip/kube-vip:v1.2.32fcdbb014a2e
github.com/osrg/gobgp/v4@v4.8.0
no fix listed

Open the chart page →

119
kube-routerenixVerified publisher1.10.01 of 1See more

kube-router enix 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-30405.

Container imageDigestPackageFixed in
cloudnativelabs/kube-router:v1.6.00ec7cd73f43f
github.com/osrg/gobgp/v3@v3.14.0
no fix listed

Open the chart page →

2,344
openelbkubesphere-stable0.5.01 of 2See more

openelb kubesphere-stable 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-30405.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.5.0b5b665c4672c
github.com/osrg/gobgp@v0.0.0-20210101133947-496b372f7b8d
no fix listed

Open the chart page →

4,329
antreaantreaVerified publisher2.7.02 of 2See more

antrea antrea 2.7.0

2 of the 2 container images this version deploys carry CVE-2026-30405.

Container imageDigestPackageFixed in
antrea/antrea-agent-ubuntu:v2.7.0c10bc45c6272
github.com/osrg/gobgp/v4@v4.8.0
no fix listed
antrea/antrea-controller-ubuntu:v2.7.0f1373d39217c
github.com/osrg/gobgp/v4@v4.8.0
no fix listed

Open the chart page →

3,231
goblackholemainVerified publisher0.0.41 of 1See more

goblackhole main 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-30405.

Container imageDigestPackageFixed in
bedag/goblackhole:0.2.0447a88598f4c
github.com/osrg/gobgp@v0.0.0-20210801043420-9e48a36ed97c
no fix listed

Open the chart page →

1,972
rke2-canalrke2-charts3.13.31 of 2See more

rke2-canal rke2-charts 3.13.3

1 of the 2 container images this version deploys carry CVE-2026-30405.

Container imageDigestPackageFixed in
rancher/hardened-calico:v3.13.36d2cd61a338b
github.com/osrg/gobgp@v0.0.0-20170802061517-bbd1d99396fe
no fix listed

Open the chart page →

6,996
ciliumcilium21.20.12 of 3See more

cilium cilium2 1.20.1

2 of the 3 container images this version deploys carry CVE-2026-30405.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.20.1ae9ea21f7427
github.com/osrg/gobgp/v4@v4.6.1-0.20260630022313-d6dee8360046
no fix listed
quay.io/cilium/operator-generic:v1.20.16c3885fc7b62
github.com/osrg/gobgp/v4@v4.6.1-0.20260630022313-d6dee8360046
no fix listed

Open the chart page →

1,708
ciliumkubeblocksVerified publisher1.15.11 of 2See more

cilium kubeblocks 1.15.1

1 of the 2 container images this version deploys carry CVE-2026-30405.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.15.1351d6685dc6f
github.com/osrg/gobgp/v3@v3.21.0
no fix listed

Open the chart page →

5,075
kube-ovnkube-ovn-test1.14.01 of 1See more

kube-ovn kube-ovn-test 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-30405.

Container imageDigestPackageFixed in
kubeovn/kube-ovn:v1.14.06722b54eb5c0
github.com/osrg/gobgp/v3@v3.37.0
no fix listed

Open the chart page →

4,940
openelbkubesphere-testVerified publisher0.2.41 of 2See more

openelb kubesphere-test 0.2.4

1 of the 2 container images this version deploys carry CVE-2026-30405.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.4.4ed7311a0f9e4
github.com/osrg/gobgp@v0.0.0-20210101133947-496b372f7b8d
no fix listed

Open the chart page →

4,329
porterkubesphere-testVerified publisher0.2.21 of 2See more

porter kubesphere-test 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-30405.

Container imageDigestPackageFixed in
kubesphere/porter:v0.4.38d1ed5ee1d2e
github.com/osrg/gobgp@v0.0.0-20210101133947-496b372f7b8d
no fix listed

Open the chart page →

2,784
loxilbloxilbVerified publisher0.1.01 of 2See more

loxilb loxilb 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-30405.

Container imageDigestPackageFixed in
ghcr.io/loxilb-io/loxilb:latestc7ede1bab641
github.com/osrg/gobgp/v3@v0.0.0-20240802091257-b91614eb13ca
no fix listed

Open the chart page →

4,424
harikubeopenshift0.16.31 of 3See more

harikube openshift 0.16.3

1 of the 3 container images this version deploys carry CVE-2026-30405.

Container imageDigestPackageFixed in
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
github.com/osrg/gobgp/v3@v3.37.0
no fix listed

Open the chart page →

2,525
harvester-cloud-providerrke2-charts0.2.15001 of 2See more

harvester-cloud-provider rke2-charts 0.2.1500

1 of the 2 container images this version deploys carry CVE-2026-30405.

Container imageDigestPackageFixed in
rancher/mirrored-kube-vip-kube-vip-iptables:v1.2.389c3f898ac5a
github.com/osrg/gobgp/v4@v4.8.0
no fix listed

Open the chart page →

437
rke2-canal-1.19-1.20rke2-charts3.13.3-build20211022021 of 2See more

rke2-canal-1.19-1.20 rke2-charts 3.13.3-build2021102202

1 of the 2 container images this version deploys carry CVE-2026-30405.

Container imageDigestPackageFixed in
rancher/hardened-calico:v3.13.3-build20210223c678c25d47c8
github.com/osrg/gobgp@v0.0.0-20170802061517-bbd1d99396fe
no fix listed

Open the chart page →

5,942
rke2-ciliumrke2-charts1.20.1032 of 3See more

rke2-cilium rke2-charts 1.20.103

2 of the 3 container images this version deploys carry CVE-2026-30405.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.20.1ae9ea21f7427
github.com/osrg/gobgp/v4@v4.6.1-0.20260630022313-d6dee8360046
no fix listed
quay.io/cilium/operator-generic:v1.20.16c3885fc7b62
github.com/osrg/gobgp/v4@v4.6.1-0.20260630022313-d6dee8360046
no fix listed

Open the chart page →

1,034

Container images carrying it

17 by charts deploying them

A fixed version is listed for 0 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/cilium/cilium:v1.20.1ae9ea21f7427
github.com/osrg/gobgp/v4@v4.6.1-0.20260630022313-d6dee8360046
no fix listed
3
quay.io/cilium/operator-generic:v1.20.16c3885fc7b62
github.com/osrg/gobgp/v4@v4.6.1-0.20260630022313-d6dee8360046
no fix listed
3
antrea/antrea-agent-ubuntu:v2.7.0c10bc45c6272
github.com/osrg/gobgp/v4@v4.8.0
no fix listed
1
antrea/antrea-controller-ubuntu:v2.7.0f1373d39217c
github.com/osrg/gobgp/v4@v4.8.0
no fix listed
1
bedag/goblackhole:0.2.0447a88598f4c
github.com/osrg/gobgp@v0.0.0-20210801043420-9e48a36ed97c
no fix listed
1
cloudnativelabs/kube-router:v1.6.00ec7cd73f43f
github.com/osrg/gobgp/v3@v3.14.0
no fix listed
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
github.com/osrg/gobgp/v3@v3.37.0
no fix listed
1
kubesphere/openelb:v0.5.0b5b665c4672c
github.com/osrg/gobgp@v0.0.0-20210101133947-496b372f7b8d
no fix listed
1
kubesphere/openelb:v0.4.4ed7311a0f9e4
github.com/osrg/gobgp@v0.0.0-20210101133947-496b372f7b8d
no fix listed
1
kubesphere/porter:v0.4.38d1ed5ee1d2e
github.com/osrg/gobgp@v0.0.0-20210101133947-496b372f7b8d
no fix listed
1
rancher/hardened-calico:v3.13.36d2cd61a338b
github.com/osrg/gobgp@v0.0.0-20170802061517-bbd1d99396fe
no fix listed
1
rancher/hardened-calico:v3.13.3-build20210223c678c25d47c8
github.com/osrg/gobgp@v0.0.0-20170802061517-bbd1d99396fe
no fix listed
1
rancher/mirrored-kube-vip-kube-vip-iptables:v1.2.389c3f898ac5a
github.com/osrg/gobgp/v4@v4.8.0
no fix listed
1
ghcr.io/kube-vip/kube-vip:v1.2.32fcdbb014a2e
github.com/osrg/gobgp/v4@v4.8.0
no fix listed
1
ghcr.io/loxilb-io/loxilb:latestc7ede1bab641
github.com/osrg/gobgp/v3@v0.0.0-20240802091257-b91614eb13ca
no fix listed
1
quay.io/cilium/cilium:v1.15.1351d6685dc6f
github.com/osrg/gobgp/v3@v3.21.0
no fix listed
1
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
github.com/osrg/gobgp/v3@v3.37.0
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.