CVE-2026-46600

EUVD-2026-46383
Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 43.93%
Debian logo
Debian Releases
Debian Product
Codename
golang-golang-x-net
bookworm
1:0.7.0+dfsg-1
fixed
bullseye
1:0.0+git20210119.5f4716e+dfsg-4
fixed
forky
1:0.58.0-1
fixed
sid
1:0.58.0-1
fixed
trixie
1:0.27.0-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang-1.23
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
kubevirt-manifests
suse enterprise sap 15 SP7
1.7.4-150700.3.33.1
fixed
suse enterprise server 15 SP7
1.7.4-150700.3.33.1
fixed
kubevirt-virtctl
suse enterprise sap 15 SP7
1.7.4-150700.3.33.1
fixed
suse enterprise server 15 SP7
1.7.4-150700.3.33.1
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
golang
Azure Linux 3.0
0:1.26.6-1.azl3
fixed