CVE-2025-11626
published 2025-10-10CVE-2025-11626: MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.11%
1.7th percentile
MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 3.4.16-0+deb11u2 (bullseye) | wireshark 3.4.16-0+deb11u2 (bullseye) |
| gitlab | wireshark | — | — |
| wireshark | wireshark | >= 0 < 3.4.16-0+deb11u2 | 3.4.16-0+deb11u2 |
| wireshark | wireshark | >= 0 < 4.4.13-0+deb13u1 | 4.4.13-0+deb13u1 |
| wireshark | wireshark | >= 0 < 4.6.0-1 | 4.6.0-1 |
| wireshark | wireshark | >= 4.2.0 < 4.2.14 | 4.2.14 |
| wireshark | wireshark | >= 4.4.0 < 4.4.10 | 4.4.10 |
| wireshark_foundation | wireshark | >= 4.2.0 < 4.2.14 | 4.2.14 |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.10 | 4.4.10 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GitLab
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
vendor_gitlab·2025-10-10·CVSS 5.5
CVE-2025-11626 [MEDIUM] CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service
Affected products: Wireshark
Affected versions: >=4.4.0, =4.2.0, <4.2.14 (affected)
Solution: Upgrade to version 4.4.10, 4.2.14, or above
Red Hat
wireshark: MONGO dissector infinite loop
vendor_redhat·2025-10-10·CVSS 5.5
CVE-2025-11626 [MEDIUM] CWE-835 wireshark: MONGO dissector infinite loop
wireshark: MONGO dissector infinite loop
MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service
A flaw was found in Wireshark’s MONGO dissector. When processing certain malformed MONGO packets, the dissector could enter an infinite loop, leading to unbounded CPU consumption. This issue allows an attacker to cause a denial of service by sending a specially crafted packet on the network or by convincing a user to open a malicious capture file.
Mitigation: No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.
Package: wireshark (Red Hat Enterprise Linux 10) - Fix deferred
Package: wireshark (Red Hat Enterprise Linux 6) - Out of support scope
Package: wir
Debian
CVE-2025-11626: wireshark - MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 al...
vendor_debian·2025·CVSS 5.5
CVE-2025-11626 [MEDIUM] CVE-2025-11626: wireshark - MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 al...
MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service
Scope: local
bookworm: open
bullseye: resolved (fixed in 3.4.16-0+deb11u2)
forky: resolved (fixed in 4.6.0-1)
sid: resolved (fixed in 4.6.0-1)
trixie: resolved (fixed in 4.4.13-0+deb13u1)
GHSA
GHSA-6vwg-gm7p-4529: MONGO dissector infinite loop in Wireshark 4
ghsa_unreviewed·2025-10-11
CVE-2025-11626 [MEDIUM] CWE-835 GHSA-6vwg-gm7p-4529: MONGO dissector infinite loop in Wireshark 4
MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service
OSV
CVE-2025-11626: MONGO dissector infinite loop in Wireshark 4
osv·2025-10-10·CVSS 5.5
CVE-2025-11626 [MEDIUM] CVE-2025-11626: MONGO dissector infinite loop in Wireshark 4
MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service
No detection rules found.
No public exploits indexed.
2025-10-10
Published