๐Ÿ” CVE Alert

CVE-2026-46600

HIGH 7.5

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

CVSS Score
7.5
EPSS Score
0.4%
EPSS Percentile
28th

Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.

Vendor go standard library
Product net
Published Jul 21, 2026
Last Updated Aug 14, 2026
Stay Ahead of the Next One

Get instant alerts for go standard library net

Be the first to know when new high vulnerabilities affecting go standard library net are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Go standard library / net
1.26.0-0 < 1.26.6 1.27.0-0 < 1.27.0-rc.3
golang.org/x/net / golang.org/x/net/dns/dnsmessage
0 < 0.56.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
go.dev: https://go.dev/cl/786345 go.dev: https://go.dev/issue/79795 groups.google.com: https://groups.google.com/g/golang-announce/c/94pEornpRlI pkg.go.dev: https://pkg.go.dev/vuln/GO-2026-5942

Credits

Mundur (https://github.com/M0nd0R)