CVE-2026-46597

An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.

  • Published May 22, 2026
  • CVSS 7.5 high
  • 0.6% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-46597 at the National Vulnerability Database