Wireshark Wireshark

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Wireshark.

By the Year

In 2026 there have been 82 vulnerabilities in Wireshark with an average score of 5.4 out of ten. Last year, in 2025 Wireshark had 7 security vulnerabilities published. That is, 75 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 1.04




Year Vulnerabilities Average Score
2026 82 5.45
2025 7 6.49
2024 19 7.09
2023 31 6.01
2022 8 6.35
2021 22 7.37
2020 20 6.58
2019 22 6.88
2018 79 7.27

It may take a day or so for new Wireshark vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Wireshark Security Vulnerabilities

Wireshark 4.6.0-4.6.8 ZigBee ZCL dissector crash (DoS)
CVE-2026-95391 5.5 - Medium - September 29, 2026

ZigBee ZCL protocol dissector crash in 4.6.0 to 4.6.8 allows denial of service

Dangling pointer

Wireshark 4.44.4.18/4.64.6.8: SCTP dissector DoS via crafted packet
CVE-2026-95389 8.1 - High - September 29, 2026

SCTP protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Heap-based Buffer Overflow

Wireshark 4.6.0-4.6.8 TTL Parser Infinite Loop DoS
CVE-2026-95386 5.5 - Medium - September 29, 2026

TTL file parser infinite loop in 4.6.0 to 4.6.8 allows denial of service

Infinite Loop

Wireshark PEAK CAN TRC Parser DOS 4.6.0-4.6.8 Fixed in 4.6.9
CVE-2026-95390 5.5 - Medium - September 29, 2026

PEAK CAN TRC file parser crash in 4.6.0 to 4.6.8 allows denial of service

NULL Pointer Dereference

Wireshark 4.6.x/4.4.x Synchrophasor Dissector Mem Leak DoS
CVE-2026-95395 5.5 - Medium - September 29, 2026

IEEE C37.118 Synchrophasor protocol dissector memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Memory Leak

Wireshark SPDY dissector DoS <4.6.9, <4.4.19
CVE-2026-95387 8.1 - High - September 29, 2026

SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Heap-based Buffer Overflow

Wireshark File Parser DoS via Large Loop (4.6.0-4.6.8, 4.4.0-4.4.18)
CVE-2026-95394 4.7 - Medium - September 29, 2026

Microsoft Network Monitor file parser large loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Unchecked Input for Loop Condition

Wireshark CSN.1 dissector crash (4.4.04.4.18, 4.6.04.6.8)
CVE-2026-95393 4.7 - Medium - September 29, 2026

CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Heap-based Buffer Overflow

Wireshark MBIM dissector DoS crash pre-4.6.9 & 4.4.19
CVE-2026-95392 5.5 - Medium - September 29, 2026

MBIM protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Buffer Over-read

Wireshark 4.4-4.6.x: Sharkd Utility Crash (DoS)
CVE-2026-95388 5.5 - Medium - September 29, 2026

Sharkd utility crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Heap-based Buffer Overflow

Wireshark Frame Protocol Metadissector Crash (DoS) 4.4.0-4.4.18, 4.6.0-4.6.8
CVE-2026-96422 5.5 - Medium - September 29, 2026

Frame protocol metadissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

assertion failure

Wireshark USB HID dissector DoS (Infinite Loop/Mem Leak) 4.6.0-4.6.8, 4.4.0-4.4.18
CVE-2026-96421 5.5 - Medium - September 29, 2026

USB HID protocol dissector infinite loop and memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Stack Exhaustion

Wireshark RF4CE dissector crash (DoS) 4.4.0-4.4.18/4.6.0-4.6.8
CVE-2026-96417 5.5 - Medium - September 29, 2026

RF4CE protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Heap-based Buffer Overflow

Wireshark 4.44.6.8/18 TIFF dissector infinite loop DoS
CVE-2026-96418 5.5 - Medium - September 29, 2026

TIFF protocol dissector infinite loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Infinite Loop

Wireshark prof import crash (DoS) - 4.4.0~4.4.18, 4.6.0~4.6.8
CVE-2026-96419 5.5 - Medium - September 29, 2026

Profile import crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service and possible code execution

Directory traversal

Wireshark 4.6.0-4.6.8 Denial of Service via Toshiba File Parser Crash
CVE-2026-96420 4.7 - Medium - September 29, 2026

Toshiba file parser crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Buffer Over-read

Wireshark X11 Dissector DoS via Crash 4.6.0-4.6.8/4.4.0-4.4.18
CVE-2026-96423 5.5 - Medium - September 29, 2026

X11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Heap-based Buffer Overflow

Wireshark <4.6.8 & <4.4.18 BUSMASTER Parser DoS
CVE-2026-76926 3.1 - Low - August 19, 2026

BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

assertion failure

Wireshark 4.6.0-4.6.7 & 4.4.0-4.4.18 Sharkd Crash for DoS
CVE-2026-76891 3.1 - Low - August 19, 2026

Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Dangling pointer

Wireshark DoS via K12xx Parser 4.4.x-4.4.17/4.6.x-4.6.7
CVE-2026-76885 3.1 - Low - August 19, 2026

Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Buffer Over-read

Wireshark 4.44.6 DoS via Bluetooth BR/EDR FHS Dissector Crash
CVE-2026-76922 5.5 - Medium - August 19, 2026

Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

NULL Pointer Dereference

Wireshark 3gpp phone log parser crash (4.4-4.6) DOS
CVE-2026-76920 4.7 - Medium - August 19, 2026

3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Memory Corruption

ESS dissector crash in Wireshark 4.4.0-4.4.17/4.6.0-4.6.7 DoS
CVE-2026-76919 5.3 - Medium - August 19, 2026

ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Use of Uninitialized Variable

Wireshark 4.6.04.6.7 & 4.4.04.4.18 BT AVRCP dissector crash (DoS)
CVE-2026-76917 5.5 - Medium - August 19, 2026

Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Heap-based Buffer Overflow

C12.22 Protocol Dissector Crash in Wireshark 4.6.0-4.6.7 & 4.4.0-4.4.18
CVE-2026-76879 7.5 - High - August 19, 2026

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Stack Overflow

Wireshark UMTS FP dissector DoS (4.6.0-4.6.7, 4.4.0-4.4.18)
CVE-2026-76889 4.7 - Medium - August 19, 2026

UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Heap-based Buffer Overflow

Wireshark RDP dissector crash 4.4.0-4.4.18 / 4.6.0-4.6.7 (DoS)
CVE-2026-76888 3.1 - Low - August 19, 2026

RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Heap-based Buffer Overflow

Wireshark 4.6.x & 4.4.x Crash: Dissection Engine DoS
CVE-2026-76887 3.1 - Low - August 19, 2026

Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Heap-based Buffer Overflow

Wireshark 4.6.0-4.6.7 / 4.4.0-4.4.17 Protocol Dissector Crash (CVE-2026-76886)
CVE-2026-76886 8.1 - High - August 19, 2026

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Heap-based Buffer Overflow

Wireshark ERF Parser DoS (4.6.04.6.7 / 4.4.04.4.18)
CVE-2026-76884 3.1 - Low - August 19, 2026

ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Buffer Over-read

Wireshark DCT2000 Parser DoS 4.4.04.4.18 & 4.6.04.6.7
CVE-2026-76883 4.7 - Medium - August 19, 2026

Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Heap-based Buffer Overflow

Wireshark 4.6.0-4.6.7 & 4.4.0-4.4.18 BAP Dissector Crash Allow DoS
CVE-2026-76882 4.7 - Medium - August 19, 2026

Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Out-of-bounds Read

Wireshark 4.6.04.6.7 TTX Logger Parser Crash -> DoS
CVE-2026-19694 4.7 - Medium - August 13, 2026

TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service

Heap-based Buffer Overflow

Denial of Service via DCT3 Trace Parser Crash in Wireshark 4.6.04.6.7
CVE-2026-19695 4.7 - Medium - August 13, 2026

Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service

Stack Overflow

Wireshark 4.6.x BLF Parser Crash DoS on Windows
CVE-2026-19696 6.6 - Medium - August 13, 2026

Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows

Memory Corruption

Wireshark 4.6.x/4.4.x BLF Parser Info Disclosure (CVE-2026-15168)
CVE-2026-15168 2.5 - Low - July 08, 2026

BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows possible information disclosure

Use of Uninitialized Variable

Wireshark 4.6.6 IEEE 802.11 dissector DoS crash
CVE-2026-15166 5.5 - Medium - July 08, 2026

IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

Stack Overflow

Wireshark Catapult DCT2000 Dissector DoS 4.4.0-4.4.16, 4.6.0-4.6.6
CVE-2026-15174 5.5 - Medium - July 08, 2026

Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

Heap-based Buffer Overflow

Wireshark 4.6.x pcapng Parser DoS Crash
CVE-2026-15173 4.7 - Medium - July 08, 2026

pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service

Heap-based Buffer Overflow

Denial of Service in Wireshark SSH Dissector CVE-2026-15171 (4.6.0-4.6.6, 4.4.0-4.4.16)
CVE-2026-15171 5.5 - Medium - July 08, 2026

SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

NULL Pointer Dereference

Wireshark 4.4.04.4.16/4.6.04.6.6 DS Etherwatch file parser DoS
CVE-2026-15167 7.5 - High - July 08, 2026

DBS Etherwatch file parser crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

Stack Overflow

Wireshark 4.4.x4.6.x Z39.50 Protocol Dissector DoS Crash
CVE-2026-15170 5.5 - Medium - July 08, 2026

Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

Heap-based Buffer Overflow

TLS ECH Decryptor Crash in Wireshark 4.6.0-4.6.6 DoS
CVE-2026-15165 5.5 - Medium - July 08, 2026

TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service

Heap-based Buffer Overflow

Wireshark 4.4.0-4.4.16/4.6.0-4.6.6 Protocol Dissector Infinite Loop DoS
CVE-2026-15163 5.5 - Medium - July 08, 2026

Multiple protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allow denial of service

Infinite Loop

Wireshark 4.44.6 ROHC Dissector Crash (DoS)
CVE-2026-9759 5.5 - Medium - May 27, 2026

ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service

NULL Pointer Dereference

Wireshark 802.11 dissector crash CVE-2026-6525 (4.6.0-4.6.4)
CVE-2026-6525 5.5 - Medium - May 02, 2026

IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4

NULL Pointer Dereference

Wireshark SBC Codec Crash DoS CVE-2026-5403 (4.4.0-4.4.14, 4.6.0-4.6.4)
CVE-2026-5403 7.8 - High - April 30, 2026

SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

Heap-based Buffer Overflow

Wireshark 4.6.x/4.4.x Path Traversal in Profile Import Causing DoS/Exec
CVE-2026-5656 7.8 - High - April 30, 2026

Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

Directory traversal

Wireshark RDP Dissector Crash (4.6.04.6.4, 4.4.04.4.14) DoS/Code Exec
CVE-2026-5405 7.8 - High - April 30, 2026

RDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

Heap-based Buffer Overflow

Wireshark 4.6.x/4.4.x Monero Dissector DoS Crash
CVE-2026-5409 5.5 - Medium - April 30, 2026

Monero protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Stack Exhaustion

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Wireshark or by Wireshark? Click the Watch button to subscribe.

Wireshark
Vendor

Wireshark
Product

subscribe