CVE-2026-46600High· 7.5▾ TwilightA flaw was found in golang.org/x/net/dns/dnsmessage. A remote attacker could send a specially crafted Service Binding (SVCB) or HTTPS resource record (RR) to a system using this component. When parsing this invalid record, the system may p…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
0.2% → 0.5%
— → 7.5
none → high
7.5 → —
high → none
— → 7.5
none → high
Last analysed / modified upstream
A flaw was found in golang.org/x/net/dns/dnsmessage. A remote attacker could send a specially crafted Service Binding (SVCB) or HTTPS resource record (RR) to a system using this component. When parsing this invalid record, the system may panic due to a parameter value overflowing the message buffer. This can lead to a Denial of Service (DoS) condition, making the affected system unavailable.
golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing — rated Important by Red Hat. Released 2026-07-21, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
Before applying this update, make sure all previously released errata relevant to your system have been applied.
The steps to apply the upgraded images are different depending on the installation plan approval policy you used when installing the cert-manager Operator for Red Hat OpenShift.
If the approval policy is set to Automatic, then the Operator will be upgraded automatically when there is a
new version of the Operator. No further action is required to upgrade. This is the default setting.
If you changed the approval policy to Manual, then you must manually approve the upgrade… https://access.redhat.com/errata/RHSA-2026:63135
Before applying this update, make sure all previously released errata relevant to your system have been applied.
The steps to apply the upgraded images are different depending on the installation plan approval policy you used when installing the cert-manager Operator for Red Hat OpenShift.
If the approval policy is set to Automatic, then the Operator will be upgraded automatically when there is a
new version of the Operator. No further action is required to upgrade. This is the default setting.
If you changed the approval policy to Manual, then you must manually approve the upgrade… https://access.redhat.com/errata/RHSA-2026:63138
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:61314
Affected packages:
golang.org/x/net < 0.56.0Patched in:
golang.org/x/net 0.56.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-44973High· 8.1github.com/go-git/go-billy: Go-billy: Arbitrary file access due to path traversal vulnerability (CVE-2026-44973)
CVE-2025-59940Medium· 6.5mkdocs-include-markdown-plugin: mkdocs-include-markdown-plugin susceptible to unvalidated input colliding with substitution placeholders (C…
CVE-2026-95897Medium· 5.5A security vulnerability has been detected in Dask up to 2026.8.0
CVE-2026-13087High· 8.8A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c
CVE-2026-94640High· 7.5A flaw was found in rpcbind
CVE-2026-90462Medium· 5.4A flaw was found in SSSD