
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-46600 is a Denial of Service vulnerability in the golang.org/x/net/dns/dnsmessage Go package that causes a panic when parsing an invalid SVCB or HTTPS DNS resource record (RR) whose parameter value size overflows the message buffer. It affects all versions of golang.org/x/net prior to 0.56.0 and was published on July 21, 2026. The CVE status is listed as "Deferred" and carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory).
The root cause is an out-of-bounds read (CWE-125, mapped to CAPEC-540: Overread Buffers) in the DNS message parser within golang.org/x/net/dns/dnsmessage. When the parser processes a malformed SVCB or HTTPS RR, it does not properly validate that the declared size of a parameter value stays within the bounds of the message buffer, leading to a buffer overread that triggers a Go runtime panic. The vulnerability requires no authentication or user interaction and is exploitable remotely over the network with low attack complexity. The fix was introduced in Go change list CL/786345 and tracked under Go issue #79795 (GitHub Advisory, Go Issue).
Successful exploitation causes the affected Go application to panic and crash, resulting in a complete loss of availability for any service that uses golang.org/x/net/dns/dnsmessage to parse DNS responses. There is no impact on confidentiality or data integrity. Downstream products that embed this library — including Grafana Tempo, Kapacitor, and others — are also affected, broadening the potential blast radius across the Go ecosystem (GitHub Advisory, InfluxData Community).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The NVD SSVC assessment classifies exploitation as "none" with the attack being "automatable" and technical impact as "partial." The EPSS score is approximately 0.155% (0.339% per GitHub Advisory), placing it in the 26th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
golang.org/x/net versions prior to 0.56.0 and expose DNS parsing functionality (e.g., DNS resolvers, proxies, or any service that processes DNS responses using the dnsmessage package).dnsmessage parser reads beyond the buffer boundary, triggering a Go runtime panic that crashes the affected service, resulting in a denial of service (GitHub Advisory, Go Issue).golang.org/x/net/dns/dnsmessage or SVCB/HTTPS RR parsing functions; repeated service crash/restart events in system logs (e.g., systemd journal showing service restarts).The primary remediation is to upgrade golang.org/x/net to version 0.56.0 or later, which contains the fix introduced in Go CL/786345. Downstream consumers such as Grafana Tempo (v2.9.4+), Kapacitor, and SUSE KubeVirt packages should also be updated to versions that incorporate the patched dependency. As a temporary network-level workaround, restrict DNS traffic to trusted resolvers and filter unexpected SVCB/HTTPS RR responses at the network perimeter. Monitor for unexpected service crashes that may indicate exploitation attempts (GitHub Advisory, SUSE Advisory, Grafana Tempo Release).
SUSE issued a security update (SUSE-SU-2026:3480-1) addressing this vulnerability in its KubeVirt packages, and openSUSE published a corresponding security announcement. InfluxData acknowledged the issue in its Kapacitor binaries via a community forum post. Tenable added detection support via Nessus plugins (329562 and 332133). No significant researcher commentary or social media discussion has been observed beyond routine vulnerability tracking (SUSE Advisory, InfluxData Community, Tenable Plugin).
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"