CVE-2026-46600: CWE-125: Out-of-bounds Read in golang.org/x/net golang.org/x/net/dns/dnsmessage
Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
AI Analysis
Technical Summary
CVE-2026-46600 is a vulnerability classified as CWE-125 (Out-of-bounds Read) in the golang.org/x/net/dns/dnsmessage package. The issue arises during parsing of invalid SVCB or HTTPS resource records where the size of a parameter value exceeds the message buffer capacity, leading to a panic condition. This vulnerability affects all versions before 0.56.0. No CVSS score or vendor advisory with patch information is currently available.
Potential Impact
The vulnerability can cause a panic in applications using the affected package when processing malformed DNS resource records, potentially leading to denial of service or application instability. There is no evidence of known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should monitor golang.org/x/net project updates for a fix in or after version 0.56.0 and plan to upgrade accordingly once available.
CVE-2026-46600: CWE-125: Out-of-bounds Read in golang.org/x/net golang.org/x/net/dns/dnsmessage
Description
Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
Affected software
pkg:golang/golang.org/x/net/dns/dnsmessageRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-46600 is a vulnerability classified as CWE-125 (Out-of-bounds Read) in the golang.org/x/net/dns/dnsmessage package. The issue arises during parsing of invalid SVCB or HTTPS resource records where the size of a parameter value exceeds the message buffer capacity, leading to a panic condition. This vulnerability affects all versions before 0.56.0. No CVSS score or vendor advisory with patch information is currently available.
Potential Impact
The vulnerability can cause a panic in applications using the affected package when processing malformed DNS resource records, potentially leading to denial of service or application instability. There is no evidence of known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should monitor golang.org/x/net project updates for a fix in or after version 0.56.0 and plan to upgrade accordingly once available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Go
- Date Reserved
- 2026-05-15T17:35:00.814Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5fcbb52a4a8d5989ac6cbb
Added to database: 07/21/2026, 19:42:45 UTC
Last enriched: 07/21/2026, 19:54:10 UTC
Last updated: 07/21/2026, 20:45:38 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.