Wireshark Wireshark

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Wireshark.

By the Year

In 2026 there have been 65 vulnerabilities in Wireshark with an average score of 5.4 out of ten. Last year, in 2025 Wireshark had 7 security vulnerabilities published. That is, 58 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 1.09




Year Vulnerabilities Average Score
2026 65 5.39
2025 7 6.49
2024 19 7.09
2023 31 6.01
2022 8 6.35
2021 22 7.37
2020 20 6.58
2019 22 6.88
2018 79 7.27

It may take a day or so for new Wireshark vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Wireshark Security Vulnerabilities

Wireshark <4.6.8 & <4.4.18 BUSMASTER Parser DoS
CVE-2026-76926 3.1 - Low - August 19, 2026

BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

assertion failure

Wireshark 4.6.0-4.6.7 & 4.4.0-4.4.18 Sharkd Crash for DoS
CVE-2026-76891 3.1 - Low - August 19, 2026

Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Dangling pointer

Wireshark DoS via K12xx Parser 4.4.x-4.4.17/4.6.x-4.6.7
CVE-2026-76885 3.1 - Low - August 19, 2026

Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Buffer Over-read

Wireshark 4.44.6 DoS via Bluetooth BR/EDR FHS Dissector Crash
CVE-2026-76922 5.5 - Medium - August 19, 2026

Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

NULL Pointer Dereference

Wireshark 3gpp phone log parser crash (4.4-4.6) DOS
CVE-2026-76920 4.7 - Medium - August 19, 2026

3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Memory Corruption

ESS dissector crash in Wireshark 4.4.0-4.4.17/4.6.0-4.6.7 DoS
CVE-2026-76919 5.3 - Medium - August 19, 2026

ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Use of Uninitialized Variable

Wireshark 4.6.04.6.7 & 4.4.04.4.18 BT AVRCP dissector crash (DoS)
CVE-2026-76917 5.5 - Medium - August 19, 2026

Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Heap-based Buffer Overflow

C12.22 Protocol Dissector Crash in Wireshark 4.6.0-4.6.7 & 4.4.0-4.4.18
CVE-2026-76879 7.5 - High - August 19, 2026

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Stack Overflow

Wireshark UMTS FP dissector DoS (4.6.0-4.6.7, 4.4.0-4.4.18)
CVE-2026-76889 4.7 - Medium - August 19, 2026

UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Heap-based Buffer Overflow

Wireshark RDP dissector crash 4.4.0-4.4.18 / 4.6.0-4.6.7 (DoS)
CVE-2026-76888 3.1 - Low - August 19, 2026

RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Heap-based Buffer Overflow

Wireshark 4.6.x & 4.4.x Crash: Dissection Engine DoS
CVE-2026-76887 3.1 - Low - August 19, 2026

Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Heap-based Buffer Overflow

Wireshark 4.6.0-4.6.7 / 4.4.0-4.4.17 Protocol Dissector Crash (CVE-2026-76886)
CVE-2026-76886 8.1 - High - August 19, 2026

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Heap-based Buffer Overflow

Wireshark ERF Parser DoS (4.6.04.6.7 / 4.4.04.4.18)
CVE-2026-76884 3.1 - Low - August 19, 2026

ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Buffer Over-read

Wireshark DCT2000 Parser DoS 4.4.04.4.18 & 4.6.04.6.7
CVE-2026-76883 4.7 - Medium - August 19, 2026

Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Heap-based Buffer Overflow

Wireshark 4.6.0-4.6.7 & 4.4.0-4.4.18 BAP Dissector Crash Allow DoS
CVE-2026-76882 4.7 - Medium - August 19, 2026

Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Out-of-bounds Read

Wireshark 4.6.04.6.7 TTX Logger Parser Crash -> DoS
CVE-2026-19694 4.7 - Medium - August 13, 2026

TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service

Heap-based Buffer Overflow

Denial of Service via DCT3 Trace Parser Crash in Wireshark 4.6.04.6.7
CVE-2026-19695 4.7 - Medium - August 13, 2026

Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service

Stack Overflow

Wireshark 4.6.x BLF Parser Crash DoS on Windows
CVE-2026-19696 6.6 - Medium - August 13, 2026

Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows

Memory Corruption

Wireshark 4.6.x/4.4.x BLF Parser Info Disclosure (CVE-2026-15168)
CVE-2026-15168 2.5 - Low - July 08, 2026

BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows possible information disclosure

Use of Uninitialized Variable

Wireshark 4.6.6 IEEE 802.11 dissector DoS crash
CVE-2026-15166 5.5 - Medium - July 08, 2026

IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

Stack Overflow

Wireshark Catapult DCT2000 Dissector DoS 4.4.0-4.4.16, 4.6.0-4.6.6
CVE-2026-15174 5.5 - Medium - July 08, 2026

Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

Heap-based Buffer Overflow

Wireshark 4.6.x pcapng Parser DoS Crash
CVE-2026-15173 4.7 - Medium - July 08, 2026

pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service

Heap-based Buffer Overflow

Denial of Service in Wireshark SSH Dissector CVE-2026-15171 (4.6.0-4.6.6, 4.4.0-4.4.16)
CVE-2026-15171 5.5 - Medium - July 08, 2026

SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

NULL Pointer Dereference

Wireshark 4.4.04.4.16/4.6.04.6.6 DS Etherwatch file parser DoS
CVE-2026-15167 7.5 - High - July 08, 2026

DBS Etherwatch file parser crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

Stack Overflow

Wireshark 4.4.x4.6.x Z39.50 Protocol Dissector DoS Crash
CVE-2026-15170 5.5 - Medium - July 08, 2026

Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

Heap-based Buffer Overflow

TLS ECH Decryptor Crash in Wireshark 4.6.0-4.6.6 DoS
CVE-2026-15165 5.5 - Medium - July 08, 2026

TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service

Heap-based Buffer Overflow

Wireshark 4.4.0-4.4.16/4.6.0-4.6.6 Protocol Dissector Infinite Loop DoS
CVE-2026-15163 5.5 - Medium - July 08, 2026

Multiple protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allow denial of service

Infinite Loop

Wireshark 4.44.6 ROHC Dissector Crash (DoS)
CVE-2026-9759 5.5 - Medium - May 27, 2026

ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service

NULL Pointer Dereference

Wireshark 802.11 dissector crash CVE-2026-6525 (4.6.0-4.6.4)
CVE-2026-6525 5.5 - Medium - May 02, 2026

IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4

NULL Pointer Dereference

Wireshark SBC Codec Crash DoS CVE-2026-5403 (4.4.0-4.4.14, 4.6.0-4.6.4)
CVE-2026-5403 7.8 - High - April 30, 2026

SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

Heap-based Buffer Overflow

Wireshark 4.6.x/4.4.x Path Traversal in Profile Import Causing DoS/Exec
CVE-2026-5656 7.8 - High - April 30, 2026

Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

Directory traversal

Wireshark RDP Dissector Crash (4.6.04.6.4, 4.4.04.4.14) DoS/Code Exec
CVE-2026-5405 7.8 - High - April 30, 2026

RDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

Heap-based Buffer Overflow

Wireshark 4.6.x/4.4.x Monero Dissector DoS Crash
CVE-2026-5409 5.5 - Medium - April 30, 2026

Monero protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Stack Exhaustion

Wireshark <=4.6.4, <=4.4.14 BT-DHT dissector DoS Crash
CVE-2026-5408 5.5 - Medium - April 30, 2026

BT-DHT protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Stack Exhaustion

Wireshark 4.6.0-4.6.4 & 4.4.0-4.4.14 ICMPv6 PvD Dissector Crash (DoS)
CVE-2026-5299 5.5 - Medium - April 30, 2026

ICMPv6 PvD protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Stack Exhaustion

Wireshark 4.6.x TLS Dissector Heap Overflow (CVE-2026-5402)
CVE-2026-5402 8.8 - High - April 30, 2026

TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution

Heap-based Buffer Overflow

SDP dissector crash before 4.6.5 Wireshark 4.6.04.6.4 Denial of Service
CVE-2026-5655 5.5 - Medium - April 30, 2026

SDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 allows denial of service

Dangling pointer

Wireshark 4.6.0-4.6.4 iLBC Codec DoS
CVE-2026-5657 5.5 - Medium - April 30, 2026

iLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Double-free

Wireshark DCP-ETSI dissector crash before 4.6.5 & 4.4.15 (DoS)
CVE-2026-5653 5.5 - Medium - April 30, 2026

DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Heap-based Buffer Overflow

Wireshark 4.6.0-4.6.4 ZigBee dissector CSF DoS
CVE-2026-6537 5.5 - Medium - April 30, 2026

ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Stack Overflow

Wireshark 4.6.0-4.6.4 DLMS/COSEM Infinite Loop in Protocol Dissector
CVE-2026-6536 5.5 - Medium - April 30, 2026

DLMS/COSEM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4

Infinite Loop

Wireshark DoS via zlib Decompress Engine (v4.6.0-4.6.4, v4.4.0-4.4.14)
CVE-2026-6535 5.5 - Medium - April 30, 2026

Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Stack Exhaustion

Wireshark 4.6.x & 4.4.x LZ77 Decompression DOS Crash (4.6.0-4.6.4)
CVE-2026-6533 5.5 - Medium - April 30, 2026

Dissection engine LZ77 decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Stack Exhaustion

Wireshark Kismet Dissector DoS <4.6.5/4.4.15
CVE-2026-6532 5.5 - Medium - April 30, 2026

Kismet protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Buffer Over-read

Wireshark SANE Dissector Infinite Loop (DoS) 4.6.0-4.6.4, 4.4.0-4.4.14
CVE-2026-6531 5.5 - Medium - April 30, 2026

SANE protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Infinite Loop

Wireshark DCP-ETSI Dissector Crash (DoS) 4.4.0-4.4.14 & 4.6.0-4.6.4
CVE-2026-6530 5.5 - Medium - April 30, 2026

DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Heap-based Buffer Overflow

Wireshark DoS via iLBC Codec in 4.4.04.4.14 & 4.6.04.6.4
CVE-2026-6529 5.5 - Medium - April 30, 2026

iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Heap-based Buffer Overflow

Wireshark 4.6.0-4.6.4 TLS Dissector Infinite Loop - DoS
CVE-2026-6528 5.5 - Medium - April 30, 2026

TLS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 allows denial of service

Infinite Loop

Wireshark 4.6.0-4.6.4 & 4.4.0-4.4.14: ASN.1 PER Disc Crash (DoS)
CVE-2026-6527 5.5 - Medium - April 30, 2026

ASN.1 PER protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Stack Exhaustion

Wireshark RTSP dissector crash 4.6.04.6.4 (before 4.6.5)
CVE-2026-6526 5.5 - Medium - April 30, 2026

RTSP protocol dissector crash in Wireshark 4.6.0 to 4.6.4

NULL Pointer Dereference

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Wireshark or by Wireshark? Click the Watch button to subscribe.

Wireshark
Vendor

Wireshark
Product

subscribe