Wireshark
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Wireshark.
By the Year
In 2026 there have been 65 vulnerabilities in Wireshark with an average score of 5.4 out of ten. Last year, in 2025 Wireshark had 7 security vulnerabilities published. That is, 58 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 1.09
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 65 | 5.39 |
| 2025 | 7 | 6.49 |
| 2024 | 19 | 7.09 |
| 2023 | 31 | 6.01 |
| 2022 | 8 | 6.35 |
| 2021 | 22 | 7.37 |
| 2020 | 20 | 6.58 |
| 2019 | 22 | 6.88 |
| 2018 | 79 | 7.27 |
It may take a day or so for new Wireshark vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Wireshark Security Vulnerabilities
Wireshark <4.6.8 & <4.4.18 BUSMASTER Parser DoS
CVE-2026-76926
3.1 - Low
- August 19, 2026
BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
assertion failure
Wireshark 4.6.0-4.6.7 & 4.4.0-4.4.18 Sharkd Crash for DoS
CVE-2026-76891
3.1 - Low
- August 19, 2026
Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Dangling pointer
Wireshark DoS via K12xx Parser 4.4.x-4.4.17/4.6.x-4.6.7
CVE-2026-76885
3.1 - Low
- August 19, 2026
Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Buffer Over-read
Wireshark 4.44.6 DoS via Bluetooth BR/EDR FHS Dissector Crash
CVE-2026-76922
5.5 - Medium
- August 19, 2026
Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
NULL Pointer Dereference
Wireshark 3gpp phone log parser crash (4.4-4.6) DOS
CVE-2026-76920
4.7 - Medium
- August 19, 2026
3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Memory Corruption
ESS dissector crash in Wireshark 4.4.0-4.4.17/4.6.0-4.6.7 DoS
CVE-2026-76919
5.3 - Medium
- August 19, 2026
ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Use of Uninitialized Variable
Wireshark 4.6.04.6.7 & 4.4.04.4.18 BT AVRCP dissector crash (DoS)
CVE-2026-76917
5.5 - Medium
- August 19, 2026
Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Heap-based Buffer Overflow
C12.22 Protocol Dissector Crash in Wireshark 4.6.0-4.6.7 & 4.4.0-4.4.18
CVE-2026-76879
7.5 - High
- August 19, 2026
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Stack Overflow
Wireshark UMTS FP dissector DoS (4.6.0-4.6.7, 4.4.0-4.4.18)
CVE-2026-76889
4.7 - Medium
- August 19, 2026
UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Heap-based Buffer Overflow
Wireshark RDP dissector crash 4.4.0-4.4.18 / 4.6.0-4.6.7 (DoS)
CVE-2026-76888
3.1 - Low
- August 19, 2026
RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Heap-based Buffer Overflow
Wireshark 4.6.x & 4.4.x Crash: Dissection Engine DoS
CVE-2026-76887
3.1 - Low
- August 19, 2026
Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Heap-based Buffer Overflow
Wireshark 4.6.0-4.6.7 / 4.4.0-4.4.17 Protocol Dissector Crash (CVE-2026-76886)
CVE-2026-76886
8.1 - High
- August 19, 2026
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Heap-based Buffer Overflow
Wireshark ERF Parser DoS (4.6.04.6.7 / 4.4.04.4.18)
CVE-2026-76884
3.1 - Low
- August 19, 2026
ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Buffer Over-read
Wireshark DCT2000 Parser DoS 4.4.04.4.18 & 4.6.04.6.7
CVE-2026-76883
4.7 - Medium
- August 19, 2026
Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Heap-based Buffer Overflow
Wireshark 4.6.0-4.6.7 & 4.4.0-4.4.18 BAP Dissector Crash Allow DoS
CVE-2026-76882
4.7 - Medium
- August 19, 2026
Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Out-of-bounds Read
Wireshark 4.6.04.6.7 TTX Logger Parser Crash -> DoS
CVE-2026-19694
4.7 - Medium
- August 13, 2026
TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service
Heap-based Buffer Overflow
Denial of Service via DCT3 Trace Parser Crash in Wireshark 4.6.04.6.7
CVE-2026-19695
4.7 - Medium
- August 13, 2026
Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service
Stack Overflow
Wireshark 4.6.x BLF Parser Crash DoS on Windows
CVE-2026-19696
6.6 - Medium
- August 13, 2026
Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows
Memory Corruption
Wireshark 4.6.x/4.4.x BLF Parser Info Disclosure (CVE-2026-15168)
CVE-2026-15168
2.5 - Low
- July 08, 2026
BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows possible information disclosure
Use of Uninitialized Variable
Wireshark 4.6.6 IEEE 802.11 dissector DoS crash
CVE-2026-15166
5.5 - Medium
- July 08, 2026
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Stack Overflow
Wireshark Catapult DCT2000 Dissector DoS 4.4.0-4.4.16, 4.6.0-4.6.6
CVE-2026-15174
5.5 - Medium
- July 08, 2026
Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Heap-based Buffer Overflow
Wireshark 4.6.x pcapng Parser DoS Crash
CVE-2026-15173
4.7 - Medium
- July 08, 2026
pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
Heap-based Buffer Overflow
Denial of Service in Wireshark SSH Dissector CVE-2026-15171 (4.6.0-4.6.6, 4.4.0-4.4.16)
CVE-2026-15171
5.5 - Medium
- July 08, 2026
SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
NULL Pointer Dereference
Wireshark 4.4.04.4.16/4.6.04.6.6 DS Etherwatch file parser DoS
CVE-2026-15167
7.5 - High
- July 08, 2026
DBS Etherwatch file parser crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Stack Overflow
Wireshark 4.4.x4.6.x Z39.50 Protocol Dissector DoS Crash
CVE-2026-15170
5.5 - Medium
- July 08, 2026
Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Heap-based Buffer Overflow
TLS ECH Decryptor Crash in Wireshark 4.6.0-4.6.6 DoS
CVE-2026-15165
5.5 - Medium
- July 08, 2026
TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
Heap-based Buffer Overflow
Wireshark 4.4.0-4.4.16/4.6.0-4.6.6 Protocol Dissector Infinite Loop DoS
CVE-2026-15163
5.5 - Medium
- July 08, 2026
Multiple protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allow denial of service
Infinite Loop
Wireshark 4.44.6 ROHC Dissector Crash (DoS)
CVE-2026-9759
5.5 - Medium
- May 27, 2026
ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service
NULL Pointer Dereference
Wireshark 802.11 dissector crash CVE-2026-6525 (4.6.0-4.6.4)
CVE-2026-6525
5.5 - Medium
- May 02, 2026
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4
NULL Pointer Dereference
Wireshark SBC Codec Crash DoS CVE-2026-5403 (4.4.0-4.4.14, 4.6.0-4.6.4)
CVE-2026-5403
7.8 - High
- April 30, 2026
SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution
Heap-based Buffer Overflow
Wireshark 4.6.x/4.4.x Path Traversal in Profile Import Causing DoS/Exec
CVE-2026-5656
7.8 - High
- April 30, 2026
Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution
Directory traversal
Wireshark RDP Dissector Crash (4.6.04.6.4, 4.4.04.4.14) DoS/Code Exec
CVE-2026-5405
7.8 - High
- April 30, 2026
RDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution
Heap-based Buffer Overflow
Wireshark 4.6.x/4.4.x Monero Dissector DoS Crash
CVE-2026-5409
5.5 - Medium
- April 30, 2026
Monero protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Stack Exhaustion
Wireshark <=4.6.4, <=4.4.14 BT-DHT dissector DoS Crash
CVE-2026-5408
5.5 - Medium
- April 30, 2026
BT-DHT protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Stack Exhaustion
Wireshark 4.6.0-4.6.4 & 4.4.0-4.4.14 ICMPv6 PvD Dissector Crash (DoS)
CVE-2026-5299
5.5 - Medium
- April 30, 2026
ICMPv6 PvD protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Stack Exhaustion
Wireshark 4.6.x TLS Dissector Heap Overflow (CVE-2026-5402)
CVE-2026-5402
8.8 - High
- April 30, 2026
TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution
Heap-based Buffer Overflow
SDP dissector crash before 4.6.5 Wireshark 4.6.04.6.4 Denial of Service
CVE-2026-5655
5.5 - Medium
- April 30, 2026
SDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 allows denial of service
Dangling pointer
Wireshark 4.6.0-4.6.4 iLBC Codec DoS
CVE-2026-5657
5.5 - Medium
- April 30, 2026
iLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Double-free
Wireshark DCP-ETSI dissector crash before 4.6.5 & 4.4.15 (DoS)
CVE-2026-5653
5.5 - Medium
- April 30, 2026
DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Heap-based Buffer Overflow
Wireshark 4.6.0-4.6.4 ZigBee dissector CSF DoS
CVE-2026-6537
5.5 - Medium
- April 30, 2026
ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Stack Overflow
Wireshark 4.6.0-4.6.4 DLMS/COSEM Infinite Loop in Protocol Dissector
CVE-2026-6536
5.5 - Medium
- April 30, 2026
DLMS/COSEM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4
Infinite Loop
Wireshark DoS via zlib Decompress Engine (v4.6.0-4.6.4, v4.4.0-4.4.14)
CVE-2026-6535
5.5 - Medium
- April 30, 2026
Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Stack Exhaustion
Wireshark 4.6.x & 4.4.x LZ77 Decompression DOS Crash (4.6.0-4.6.4)
CVE-2026-6533
5.5 - Medium
- April 30, 2026
Dissection engine LZ77 decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Stack Exhaustion
Wireshark Kismet Dissector DoS <4.6.5/4.4.15
CVE-2026-6532
5.5 - Medium
- April 30, 2026
Kismet protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Buffer Over-read
Wireshark SANE Dissector Infinite Loop (DoS) 4.6.0-4.6.4, 4.4.0-4.4.14
CVE-2026-6531
5.5 - Medium
- April 30, 2026
SANE protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Infinite Loop
Wireshark DCP-ETSI Dissector Crash (DoS) 4.4.0-4.4.14 & 4.6.0-4.6.4
CVE-2026-6530
5.5 - Medium
- April 30, 2026
DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Heap-based Buffer Overflow
Wireshark DoS via iLBC Codec in 4.4.04.4.14 & 4.6.04.6.4
CVE-2026-6529
5.5 - Medium
- April 30, 2026
iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Heap-based Buffer Overflow
Wireshark 4.6.0-4.6.4 TLS Dissector Infinite Loop - DoS
CVE-2026-6528
5.5 - Medium
- April 30, 2026
TLS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 allows denial of service
Infinite Loop
Wireshark 4.6.0-4.6.4 & 4.4.0-4.4.14: ASN.1 PER Disc Crash (DoS)
CVE-2026-6527
5.5 - Medium
- April 30, 2026
ASN.1 PER protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Stack Exhaustion
Wireshark RTSP dissector crash 4.6.04.6.4 (before 4.6.5)
CVE-2026-6526
5.5 - Medium
- April 30, 2026
RTSP protocol dissector crash in Wireshark 4.6.0 to 4.6.4
NULL Pointer Dereference