A vulnerability identified as critical has been detected in Google Go up to 0.55.x. This issue affects some unknown processing of the component x/net/dns/dnsmessage. Performing a manipulation results in out-of-bounds read.

This vulnerability was named CVE-2026-46600. The attack may be initiated remotely. There is no available exploit.