PT-2026-62048 · Alpaquita+11 · Buildah+39

·

CVE-2026-46600

·

Published

2026-07-14

·

Updated

2026-09-08

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description Parsing an invalid SVCB (Service Binding) or HTTPS RR (Resource Record) can cause a panic when the size of a parameter value overflows the message buffer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-93198
BIT-GOLANG-2026-46600
CLEANSTART-2026-BF01272
CLEANSTART-2026-EP65920
CLEANSTART-2026-GY91527
CLEANSTART-2026-JT42679
CLEANSTART-2026-JV36933
CLEANSTART-2026-KB08955
CLEANSTART-2026-KL21881
CLEANSTART-2026-LD95637
CLEANSTART-2026-LN45890
CLEANSTART-2026-OM32721
CLEANSTART-2026-PH23874
CLEANSTART-2026-PY84482
CLEANSTART-2026-RV11606
CLEANSTART-2026-SO86245
CLEANSTART-2026-VA62549
CLEANSTART-2026-VU72808
CLEANSTART-2026-VY16523
CLEANSTART-2026-WT22902
CVE-2026-46600
GO-2026-5942
OPENSUSE-SU-2026:11392-1
OPENSUSE-SU-2026:11727-1
OPENSUSE-SU-2026:21483-1
OPENSUSE-SU-2026:21590-1
OPENSUSE-SU-2026:21761-1
SUSE-SU-2026:3480-1
SUSE-SU-2026:3630-1

Affected Products

Buildah
Calicoctl
Cilium-Cli
Kubernetes Containerd
Cortex
Cri-Tools
Docker-Cli-Buildx
Dynatrace-Operator
Etcd
External Secrets Operator
Go
Golang
Golang-1.23
Golang-Golang-X-Net
Golang.Org/X/Net
Golang.Org/X/Net/Dns/Dnsmessage
Govulncheck-Vulndb
Grype
Ingress-Nginx-Controller-1.13
Ingress-Nginx-Controller-1.14
Ingress-Nginx-Controller-1.15
Knative Serving
Kube-Vip
Kubevirt
Kubevirt-1.6
Kubevirt-1.8
Mongodb
Net
Osv-Scanner
Podman
Prometheus
Rclone
Rootio-Golang.Org/X/Net
Rootlesskit
Runc
Sealed-Secrets
Stakater-Reloader
Stdlib
Trust-Manager
Wave