cbcvebase.
CVE-2026-46597
published 2026-05-22

CVE-2026-46597: An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.

PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.47%
39.8th percentile
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.

Affected

184 ranges· showing 25
VendorProductVersion rangeFixed in
advanced-cluster-securityrhacs-main-rhel8——
advanced-cluster-securityrhacs-rhel8-operator——
advanced-cluster-securityrhacs-roxctl-rhel8——
advanced-cluster-securityrhacs-scanner-rhel8_1782891812——
advanced-cluster-securityrhacs-scanner-slim-rhel8_1782891812——
advanced-cluster-securityrhacs-scanner-v4-rhel8_1783357116——
assistedagent-preinstall-image-builder-rhel9——
buildah_projectbuildah——
cert-managerjetstack-cert-manager-acmesolver-rhel9——
cert-managerjetstack-cert-manager-rhel9——
complianceopenshift-security-profiles-operator-bundle——
complianceopenshift-security-profiles-rhel8-operator——
confidential-containerstrustee——
container-native-virtualizationvirt-api-rhel9——
container-native-virtualizationvirt-artifacts-server-rhel9——
container-native-virtualizationvirt-controller-rhel9——
container-native-virtualizationvirt-exportproxy-rhel9——
container-native-virtualizationvirt-exportserver-rhel9——
container-native-virtualizationvirt-handler-rhel9——
container-native-virtualizationvirt-launcher-rhel9——
container-native-virtualizationvirt-operator-rhel9——
container-tools_rhel8buildah——
container-tools_rhel8podman——
cryostatcryostat-storage-rhel9——
devspacestraefik-rhel9——

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.