VDB
CVE-2026-46600
CVE-2026-46600
PUBLISHED
CVSS 7.5 HIGH
Reported by Go · Published July 21, 2026
Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Go standard library | net | 1.26.0-0, 1.27.0-0 |
| golang.org/x/net | golang.org/x/net/dns/dnsmessage | 0 |
| chainguard | gpu-operator-fips-25.3 | *, *, * |
| wolfi | apisix-ingress-controller | *, *, * |
| chainguard | tigera-operator-1.29 | 0, 0 |
| wolfi | rke2-cloud-provider | *, *, * |
| chainguard | prometheus-blackbox-exporter | *, *, * |
| chainguard | consul-k8s-1.4 | *, *, * |
| wolfi | logstash-exporter | * |
| chainguard | datadog-agent-fips-7.79 | *, *, * |
| chainguard | crossplane-provider-kubernetes-fips | *, *, * |
| chainguard | rancher-security-scan-0.6 | * |
| chainguard | gcp-compute-persistent-disk-csi-driver-1.17 | *, *, * |
| chainguard | crossplane-provider-aws-cognitoidp | *, *, * |
| chainguard | github-mcp-server | *, *, * |
| wolfi | whereabouts | *, *, * |
| chainguard | kubescape-server | *, *, * |
| wolfi | kube-logging-operator | *, *, * |
| chainguard | eks-distro-fips-1.31 | *, *, * |
| chainguard | kcp-0.31 | *, *, * |
…and 3194 more
Timeline
- Jul 21, 2026 CVE Published
- Jul 22, 2026 Coalition ESS Score
- Aug 7, 2026 EPSS Score