CLEANSTART-2026-HA46232
Dashboard / Vulnerabilities / CLEANSTART-2026-HA46232
CLEANSTART-2026-HA46232
Summary: Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer
Details: Multiple security vulnerabilities affect the metallb package. Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. See references for individual vulnerability details.
References: https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-HA46232.json, https://osv.dev/vulnerability/CVE-2023-45288, https://osv.dev/vulnerability/CVE-2024-24786, https://osv.dev/vulnerability/CVE-2026-14362, https://osv.dev/vulnerability/CVE-2026-33818, https://osv.dev/vulnerability/CVE-2026-39821, https://osv.dev/vulnerability/CVE-2026-46600, https://osv.dev/vulnerability/CVE-2026-56852, https://osv.dev/vulnerability/CVE-2026-56853, https://osv.dev/vulnerability/CVE-2026-56858, https://osv.dev/vulnerability/CVE-2026-56859, https://osv.dev/vulnerability/CVE-2026-56860, https://osv.dev/vulnerability/CVE-2026-56862, https://osv.dev/vulnerability/ghsa-4v7x-pqxf-cx7m, https://osv.dev/vulnerability/ghsa-8r3f-844c-mc37, https://nvd.nist.gov/vuln/detail/CVE-2023-45288, https://nvd.nist.gov/vuln/detail/CVE-2024-24786, https://nvd.nist.gov/vuln/detail/CVE-2026-14362, https://nvd.nist.gov/vuln/detail/CVE-2026-33818, https://nvd.nist.gov/vuln/detail/CVE-2026-39821, https://nvd.nist.gov/vuln/detail/CVE-2026-46600, https://nvd.nist.gov/vuln/detail/CVE-2026-56852, https://nvd.nist.gov/vuln/detail/CVE-2026-56853, https://nvd.nist.gov/vuln/detail/CVE-2026-56858, https://nvd.nist.gov/vuln/detail/CVE-2026-56859, https://nvd.nist.gov/vuln/detail/CVE-2026-56860, https://nvd.nist.gov/vuln/detail/CVE-2026-56862
Affected packages
Package
Name: metallb
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
