Knative serving: Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer (CVE-2026-46600)
Knative-serving version 1.22.1-r0 addresses two security vulnerabilities including CVE-2026-46600. The vulnerabilities affect multiple versions of knative-serving prior to 1.22.1-r0 and other specified ranges. A patch is available to remediate these issues. No CVSS score is provided, but the severity is assessed as high based on the information given.
AI Analysis
Technical Summary
The knative-serving package contains a security vulnerability (CVE-2026-46600) where parsing an invalid SVCB or HTTPS RR can trigger a panic due to an overflow in the message buffer caused by the size of a parameter value. This vulnerability affects multiple versions of knative-serving, including =1.10.0-r1, versions from 1.26.0 up to but not including 1.26.6, versions less than 3.0.3-r1, less than 2.9.5-r1, and less than 1.22.1-r0. The vulnerability can cause service disruption through panic-induced crashes. A patch is available to remediate this issue.
Potential Impact
The vulnerability can cause the knative-serving component to panic and crash when processing specially crafted invalid SVCB or HTTPS resource records with oversized parameter values. This results in denial of service by interrupting normal service operation. There is no indication of code execution or data leakage from the provided information.
Mitigation Recommendations
A patch is available for this vulnerability. Users should apply the official fix by upgrading to versions of knative-serving that include the patch. Specific patched versions are not listed here, so users should consult the vendor or official advisories for exact fixed versions and upgrade accordingly.
Knative serving: Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer (CVE-2026-46600)
Description
Knative-serving version 1.22.1-r0 addresses two security vulnerabilities including CVE-2026-46600. The vulnerabilities affect multiple versions of knative-serving prior to 1.22.1-r0 and other specified ranges. A patch is available to remediate these issues. No CVSS score is provided, but the severity is assessed as high based on the information given.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The knative-serving package contains a security vulnerability (CVE-2026-46600) where parsing an invalid SVCB or HTTPS RR can trigger a panic due to an overflow in the message buffer caused by the size of a parameter value. This vulnerability affects multiple versions of knative-serving, including =1.10.0-r1, versions from 1.26.0 up to but not including 1.26.6, versions less than 3.0.3-r1, less than 2.9.5-r1, and less than 1.22.1-r0. The vulnerability can cause service disruption through panic-induced crashes. A patch is available to remediate this issue.
Potential Impact
The vulnerability can cause the knative-serving component to panic and crash when processing specially crafted invalid SVCB or HTTPS resource records with oversized parameter values. This results in denial of service by interrupting normal service operation. There is no indication of code execution or data leakage from the provided information.
Mitigation Recommendations
A patch is available for this vulnerability. Users should apply the official fix by upgrading to versions of knative-serving that include the patch. Specific patched versions are not listed here, so users should consult the vendor or official advisories for exact fixed versions and upgrade accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- CLEANSTART-2026-LP75251
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Alpine"]
- State
- PUBLISHED
Threat ID: 6a7f4430bf8831d53963c006
Added to database: 08/14/2026, 16:37:04 UTC
Last enriched: 09/09/2026, 15:14:21 UTC
Last updated: 09/27/2026, 01:47:42 UTC
Views: 46
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.