CVE-2025-11626Infinite Loop in Foundation Wireshark

CWE-835Infinite Loop6 documents6 sources
Severity
5.5MEDIUMNVD
EPSS
0.0%
top 99.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 10
Latest updateOct 11

Description

MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

NVDwireshark/wireshark4.2.04.2.14+1
CVEListV5wireshark_foundation/wireshark4.4.04.4.10+1
Debianwireshark/wireshark< 3.4.16-0+deb11u2+2

🔴Vulnerability Details

3
GHSA
GHSA-6vwg-gm7p-4529: MONGO dissector infinite loop in Wireshark 42025-10-11
OSV
CVE-2025-11626: MONGO dissector infinite loop in Wireshark 42025-10-10
CVEList
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark2025-10-10

📋Vendor Advisories

2
Red Hat
wireshark: MONGO dissector infinite loop2025-10-10
Debian
CVE-2025-11626: wireshark - MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 al...2025
CVE-2025-11626 — Infinite Loop in Foundation Wireshark | cvebase