CVE-2026-26514

Name
CVE-2026-26514
Description
An Argument Injection vulnerability exists in bird-lg-go before commit 6187a4e. The traceroute module uses shlex.Split to parse user input without validation, allowing remote attackers to inject arbitrary flags (e.g., -w, -q) via the q parameter. This can be exploited to cause a Denial of Service (DoS) by exhausting system resources.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://github.com/xddxdd/bird-lg-go/commit/6187a4e3afce6d8c29568f8c72ca497d1f5a2b56
cve@mitre.org https://github.com/xddxdd/bird-lg-go/issues/136

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:xddxdd:bird-lg-go:*:*:*:*:*:go:*:* bird-lg-go >= None < 1.4.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
bird-lg-go edge-community 1.4.0-r5 Thomas Liske <thomas@fiasko-nw.net> possibly vulnerable
bird-lg-go edge-community 1.4.0-r4 Thomas Liske <thomas@fiasko-nw.net> possibly vulnerable
bird-lg-go edge-community 1.4.0-r3 Thomas Liske <thomas@fiasko-nw.net> possibly vulnerable
bird-lg-go edge-community 1.4.0-r2 Thomas Liske <thomas@fiasko-nw.net> possibly vulnerable
bird-lg-go edge-community 1.4.0-r1 Thomas Liske <thomas@fiasko-nw.net> possibly vulnerable
bird-lg-go edge-community 1.4.0-r0 Thomas Liske <thomas@fiasko-nw.net> possibly vulnerable
bird-lg-go edge-community 1.3.12.1-r0 Thomas Liske <thomas@fiasko-nw.net> possibly vulnerable
bird-lg-go edge-community 1.3.8-r9 Thomas Liske <thomas@fiasko-nw.net> possibly vulnerable
bird-lg-go edge-community 1.3.8-r8 Thomas Liske <thomas@fiasko-nw.net> possibly vulnerable
bird-lg-go edge-community 1.3.8-r7 Thomas Liske <thomas@fiasko-nw.net> possibly vulnerable
bird-lg-go edge-community 1.3.8-r6 Thomas Liske <thomas@fiasko-nw.net> possibly vulnerable
bird-lg-go edge-community 1.3.8-r5 Thomas Liske <thomas@fiasko-nw.net> possibly vulnerable
bird-lg-go edge-community 1.3.8-r4 Thomas Liske <thomas@fiasko-nw.net> possibly vulnerable
bird-lg-go edge-community 1.3.8-r3 Thomas Liske <thomas@fiasko-nw.net> possibly vulnerable
bird-lg-go edge-community 1.3.8-r2 Thomas Liske <thomas@fiasko-nw.net> possibly vulnerable
bird-lg-go edge-community 1.3.8-r1 Thomas Liske <thomas@fiasko-nw.net> possibly vulnerable
bird-lg-go edge-community 1.3.8-r0 Thomas Liske <thomas@fiasko-nw.net> possibly vulnerable
bird-lg-go edge-community 1.3.7.1-r4 Thomas Liske <thomas@fiasko-nw.net> possibly vulnerable
bird-lg-go 3.23-community 1.4.0-r5 Thomas Liske <thomas@fiasko-nw.net> possibly vulnerable
bird-lg-go 3.23-community 1.4.0-r4 Thomas Liske <thomas@fiasko-nw.net> possibly vulnerable
bird-lg-go 3.23-community 1.4.0-r3 Thomas Liske <thomas@fiasko-nw.net> possibly vulnerable
bird-lg-go 3.23-community 1.4.0-r2 Thomas Liske <thomas@fiasko-nw.net> possibly vulnerable
bird-lg-go 3.23-community 1.4.0-r1 Thomas Liske <thomas@fiasko-nw.net> possibly vulnerable