Vulnerability Description
FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IPv4UnicastAnnounce::get_attributes() function computes attribute_length as 'sizeof(bgp_as_path_segment_element_t) + this->as_path_asns.size() * sizeof(uint32_t)' and stores it in a uint8_t field (line 600-605). Since uint8_t can only hold values 0-255, an AS_PATH containing more than 63 ASNs (2 + 64*4 = 258 > 255) causes silent truncation. The truncated length is used for buffer sizing, while the actual data written is the full untruncated amount, resulting in a heap buffer overflow. Similarly, the path_segment_length field at line 621 is also uint8_t, truncating with more than 255 ASNs.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pavel-Odintsov | Fastnetmon | <= 1.2.9 |
Related Weaknesses (CWE)
References
- https://github.com/pavel-odintsov/fastnetmonProduct
- https://github.com/pavel-odintsov/fastnetmon/blob/master/src/bgp_protocol.hppProduct
- https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48691-bgp-as-path-overflowThird Party Advisory
FAQ
What is CVE-2026-48691?
CVE-2026-48691 is a vulnerability with a CVSS score of 9.8 (CRITICAL). FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IPv4UnicastAnnounce::get_attributes() function computes attri...
How severe is CVE-2026-48691?
CVE-2026-48691 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-48691?
Check the references section above for vendor advisories and patch information. Affected products include: Pavel-Odintsov Fastnetmon.