Review reviewHigh
CVE-2026-46600
golang.org/x/net golang.org/x/net/dns/dnsmessage
Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
- CVSS
- 7.5
- EPSS
- 0.34% 26.5% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.22