CVE-2026-46597: Integer Overflow Before Cast Bounds Check

An arithmetic operation evaluating before a type cast can cause an integer overflow. When calculating values of smaller types (like `byte` or `uint32`) before casting them to `int`, the arithmetic might exceed the maximum capacity of the smaller type and wrap around. This causes the subsequent bound checks to evaluate an incorrect, significantly smaller valu

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Go
greprules fetch cve-2026-46597-integer-overflow-before-cast-bounds-check --engine opengrep

Description

An arithmetic operation evaluating before a type cast can cause an integer overflow. When calculating values of smaller types (like `byte` or `uint32`) before casting them to `int`, the arithmetic might exceed the maximum capacity of the smaller type and wrap around. This causes the subsequent bound checks to evaluate an incorrect, significantly smaller valu