Skip to main content
EPSS 0.6%top 52%

Knative serving: Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer (CVE-2026-46600)

0
High
Published: 07/22/2026 (07/22/2026, 00:33:38 UTC)
Source: GCVE Database
Product: knative-serving

Description

Knative-serving version 1.22.1-r0 addresses two security vulnerabilities including CVE-2026-46600. The vulnerabilities affect multiple versions of knative-serving prior to 1.22.1-r0 and other specified ranges. A patch is available to remediate these issues. No CVSS score is provided, but the severity is assessed as high based on the information given.

Affected software

Alpineghsa
dynatrace-operator
Affected versions
<1.10.0-r1=1.10.0-r1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/09/2026, 15:14:21 UTC

Technical Analysis

The knative-serving package contains a security vulnerability (CVE-2026-46600) where parsing an invalid SVCB or HTTPS RR can trigger a panic due to an overflow in the message buffer caused by the size of a parameter value. This vulnerability affects multiple versions of knative-serving, including =1.10.0-r1, versions from 1.26.0 up to but not including 1.26.6, versions less than 3.0.3-r1, less than 2.9.5-r1, and less than 1.22.1-r0. The vulnerability can cause service disruption through panic-induced crashes. A patch is available to remediate this issue.

Potential Impact

The vulnerability can cause the knative-serving component to panic and crash when processing specially crafted invalid SVCB or HTTPS resource records with oversized parameter values. This results in denial of service by interrupting normal service operation. There is no indication of code execution or data leakage from the provided information.

Mitigation Recommendations

A patch is available for this vulnerability. Users should apply the official fix by upgrading to versions of knative-serving that include the patch. Specific patched versions are not listed here, so users should consult the vendor or official advisories for exact fixed versions and upgrade accordingly.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
CLEANSTART-2026-LP75251
Osv Schema Version
1.7.3
Ecosystems
["Alpine"]
State
PUBLISHED

Threat ID: 6a7f4430bf8831d53963c006

Added to database: 08/14/2026, 16:37:04 UTC

Last enriched: 09/09/2026, 15:14:21 UTC

Last updated: 09/27/2026, 01:47:42 UTC

Views: 46

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses