Home

Description

An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.

PUBLISHED Reserved 2026-05-15 | Published 2026-05-22 | Updated 2026-05-22 | Assigner Go

Problem types

CWE-191: Integer Underflow (Wrap or Wraparound)

Product status

Default status
unaffected

Any version before 0.52.0
affected

Credits

Maciej Kawka

References

go.dev/issue/79561

groups.google.com/g/golang-announce/c/a082jnz-LvI

go.dev/cl/781620

pkg.go.dev/vuln/GO-2026-5013

cve.org (CVE-2026-46597)

nvd.nist.gov (CVE-2026-46597)

Download JSON