CVE-2026-46600 — golang
CVE-2026-46600 is a Out-of-bounds Read vulnerability in golang. A fix is available for golang — see the affected versions and patch details below.
Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
Exploitation Status
No confirmed exploitation observed yet
- CISA assesses this as automatable — exploitation doesn’t require manual, per-target effort, which raises the odds of mass scanning and opportunistic attacks.
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for CVE-2026-46600.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
Real-World Exposure
golangReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects Bitnami packages — download data is not available via public APIs for these ecosystems.
Description
Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 📦Bitnami | golang | ≥ 1.26.0&&< 1.26.6 | 1.26.6 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for golang, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update golang to 1.26.6 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-46600 is resolved across your whole dependency graph.
Workarounds
Stop feeding it untrusted input: reject or quarantine files and payloads from unverified sources until you can upgrade, restrict accepted formats to the ones you actually need, and run the parsing or decoding step in a least-privileged sandbox or short-lived worker so a crash or corrupted read cannot reach the rest of the process.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
| Product | Fixed in | Advisory |
|---|---|---|
| Cert Manager support for Red Hat OpenShift release 1.19 | cert-manager/cert-manager-operator-rhel9:1788348522 | RHSA-2026:63135 |
| Cert Manager support for Red Hat OpenShift release 1.19 | cert-manager/jetstack-cert-manager-acmesolver-rhel9:1788348571 | RHSA-2026:63138 |
| Cert Manager support for Red Hat OpenShift release 1.20 | cert-manager/jetstack-cert-manager-rhel9:1790223279 | RHSA-2026:72394 |
| Cert Manager support for Red Hat OpenShift release 1.20 | cert-manager/cert-manager-istio-csr-rhel9:1790223719 | RHSA-2026:72395 |
| Cert Manager support for Red Hat OpenShift release 1.20 | cert-manager/cert-manager-operator-rhel9:1790272426 | RHSA-2026:72399 |
| Cert Manager support for Red Hat OpenShift release 1.20 | cert-manager/jetstack-cert-manager-acmesolver-rhel9:1790589998 | RHSA-2026:72470 |
| Cert Manager support for Red Hat OpenShift release 1.20 | cert-manager/cert-manager-istio-csr-rhel9:1790589914 | RHSA-2026:72475 |
| Cert Manager support for Red Hat OpenShift release 1.20 | cert-manager/cert-manager-operator-rhel9:1790589855 | RHSA-2026:72476 |
Frequently Asked Questions
Is CVE-2026-46600 in your dependencies?
Find it across Bitnami, including transitive dependencies.