osv:CLEANSTART-2026-SG10675
incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs
none
Description
CVE-2026-46597 affects multiple packages. An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs. See references for individual vulnerability details.
Source: OSV