CVE-2026-46600
ADVISORY - debianSummary
Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
- golang-golang-x-net 1:0.56.0-1 [trixie] - golang-golang-x-net (Vulnerable code introduced later) [bookworm] - golang-golang-x-net (SVCB/HTTPS RR support not present; dns/dnsmessage/svcb.go and unpackSVCBResource introduced in x/net v0.47.0) [bullseye] - golang-golang-x-net (SVCB/HTTPS RR support not present; dns/dnsmessage/svcb.go and unpackSVCBResource introduced in x/net v0.47.0) https://github.com/golang/go/issues/79795 Fixed by: https://github.com/golang/net/commit/82e7868a02167540748b74780b0bf825985256f7 (v0.56.0) Introduced with: https://github.com/golang/net/commit/bb2055dafd28a92822d2297d3121c7498d58f1f6 (v0.47.0)
EPSS Scoreโ : 0.00339 (0.266)
Common Weakness Enumeration (CWE)
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in