CVE-2026-46600
High
Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
Exploit probability
0.3%
Published
July 14, 2026
Required by
Not available
Last source change
August 17, 2026
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
GO-2026-5942
View original source
Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
Open Source Vulnerabilities
BIT-golang-2026-46600
View original source
Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
05 / REFERENCES