CVE-2026-49943 affects CZ.NIC BIRD Internet Routing Daemon through 2.19.0. The flaw is a stack-based buffer overflow in the BGP AS_PATH mask matching implementation in nest/a-path.c. Specifically, as_path_match() uses a fixed-size stack array sized for 2048 + 1 pm_pos entries, but parse_path() expands AS_PATH segments from a received BGP UPDATE without enforcing a matching upper bound. When RFC 8654 BGP Extended Messages are enabled and a BIRD filter evaluates an AS path mask expression such as "bgp_path ~ [= ... =]", an established BGP peer can supply a long AS_PATH containing more than 2048 expanded ASNs. This causes writes past the end of the fixed stack buffer in parse_path()/as_path_match(), leading to daemon termination.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Small repository containing a Python proof-of-concept (`poc.py`) plus documentation (`README.md`, `advisory.md`) for CVE-2026-49943, a stack-based buffer overflow in BIRD/BIRD2 BGP AS_PATH mask matching. The exploit is a standalone Python script, not tied to a common framework. Its structure is simple: helper functions build and send BGP OPEN, KEEPALIVE, and a malicious UPDATE message; `main()` handles CLI arguments, TCP connection setup, minimal BGP handshake, and exploit delivery. The exploit capability is denial of service against a vulnerable BIRD instance. It connects to a target BGP service (default TCP/179), negotiates capabilities including Extended Message support, and sends a crafted UPDATE whose AS_PATH contains 2295 4-byte ASNs across 9 AS_SEQUENCE segments. This is intended to exceed the vulnerable fixed-size `pm_pos pos[2048 + 1]` stack buffer described in the advisory when the target evaluates an AS path mask filter. The script does not provide code execution or a shell; it aims to crash the daemon, inferred by connection reset/timeout after sending the UPDATE. Repository purpose is to document and demonstrate the vulnerability conditions and a practical crash trigger. The advisory explains the vulnerable code path, affected versions, attack prerequisites, and mitigation guidance. Based on the included code and documentation, this is a real exploit PoC for a network-reachable but authenticated/peer-required BGP attack scenario, with operational exploit logic but a fixed, hardcoded payload.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.