CVE-2026-46600
Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
| Vendor | golang.org/x/net |
| Product | golang.org/x/net/dns/dnsmessage |
| Published | Jul 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for golang.org/x/net golang.org/x/net/dns/dnsmessage
Be the first to know when new unknown vulnerabilities affecting golang.org/x/net golang.org/x/net/dns/dnsmessage are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
golang.org/x/net / golang.org/x/net/dns/dnsmessage
0 < 0.56.0
References
Credits
Mundur (https://github.com/M0nd0R)