Go standard library net

3 known vulnerabilities in Go standard library net, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-46600 CVSS 7.5 high Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
  • CVE-2026-39836 CVSS 7.5 high The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).
  • CVE-2026-33811 CVSS 7.5 high When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.