CVE-2026-46600
Description
Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
Metadata
Severity & Metrics
No CVSS data available.
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| golang.org/x/net | golang.org/x/net/dns/dnsmessage | — | 0 < 0.56.0 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | CWE-125: Out-of-bounds Read |
References (3)