CVE-2026-0960
published 2026-01-14CVE-2026-0960: HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service
PriorityP417medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.12%
2.4th percentile
HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 3.4.16-0+deb11u2 (bullseye) | wireshark 3.4.16-0+deb11u2 (bullseye) |
| gitlab | wireshark | — | — |
| wireshark | wireshark | >= 0 < 3.4.16-0+deb11u2 | 3.4.16-0+deb11u2 |
| wireshark | wireshark | >= 0 < 4.4.13-0+deb13u1 | 4.4.13-0+deb13u1 |
| wireshark | wireshark | >= 0 < 4.6.3-1 | 4.6.3-1 |
| wireshark | wireshark | >= 4.4.0 < 4.4.13 | 4.4.13 |
| wireshark | wireshark | >= 4.6.0 < 4.6.3 | 4.6.3 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.3 | 4.6.3 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2026-0960: HTTP3 protocol dissector infinite loop in Wireshark 4
osv·2026-01-14·CVSS 5.5
CVE-2026-0960 [MEDIUM] CVE-2026-0960: HTTP3 protocol dissector infinite loop in Wireshark 4
HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service
GHSA
GHSA-6fx5-r2fx-fjcr: HTTP3 protocol dissector infinite loop in Wireshark 4
ghsa_unreviewed·2026-01-14
CVE-2026-0960 [MEDIUM] CWE-835 GHSA-6fx5-r2fx-fjcr: HTTP3 protocol dissector infinite loop in Wireshark 4
HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service
Red Hat
Wireshark: Wireshark: Denial of Service via HTTP3 protocol dissector infinite loop
vendor_redhat·2026-01-14·CVSS 4.7
CVE-2026-0960 [MEDIUM] CWE-835 Wireshark: Wireshark: Denial of Service via HTTP3 protocol dissector infinite loop
Wireshark: Wireshark: Denial of Service via HTTP3 protocol dissector infinite loop
HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service
A flaw was found in Wireshark. A local user could be affected by a denial of service when opening a specially crafted capture file containing HTTP3 protocol traffic. This vulnerability is caused by an infinite loop within the HTTP3 protocol dissector, leading to the application becoming unresponsive.
Statement: This vulnerability is rated Moderate for Red Hat Enterprise Linux and Red Hat In-Vehicle OS. The flaw in the Wireshark HTTP3 protocol dissector can lead to a denial of service when processing a specially crafted HTTP3 packet. This affects systems where Wireshark is used to analyze network traffic, potentiall
GitLab
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
vendor_gitlab·2026-01-14·CVSS 5.5
CVE-2026-0960 [MEDIUM] CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, <4.6.3 (affected)
Solution: Upgrade to version 4.6.3 or above
Credit: Tom Needham
Debian
CVE-2026-0960: wireshark - HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial...
vendor_debian·2026·CVSS 4.7
CVE-2026-0960 [MEDIUM] CVE-2026-0960: wireshark - HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial...
HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service
Scope: local
bookworm: open
bullseye: resolved (fixed in 3.4.16-0+deb11u2)
forky: resolved (fixed in 4.6.3-1)
sid: resolved (fixed in 4.6.3-1)
trixie: resolved (fixed in 4.4.13-0+deb13u1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-0960 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.7
CVE-2026-0960 [MEDIUM] CVE-2026-0960 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0960 :
Wireshark vulnerability analysis and mitigation
HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service
Source : NVD
## 5.5
Score
Published January 14, 2026
Severity MEDIUM
CNA Score 4.7
Affected Technologies
Wireshark
Linux Fedora
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libvirt-libs
libwireshark19
Sources
Alpine 3.21, edge Severity MEDIUM No Fix Added at: Jan 23, 2026
Alpine 3.22, 3.23 Severity MEDIUM No Fix Added at: Jan 28, 2026
Debian 11, 13, 14 Severity MEDIUM Has Fix Added at: Jan 18, 2026
Debian 12 Severity MEDIUM No Fix Added at: Jan
Bugzilla
CVE-2026-0960 Wireshark: Wireshark: Denial of Service via HTTP3 protocol dissector infinite loop
bugzilla·2026-01-14·CVSS 5.5
CVE-2026-0960 [MEDIUM] CVE-2026-0960 Wireshark: Wireshark: Denial of Service via HTTP3 protocol dissector infinite loop
CVE-2026-0960 Wireshark: Wireshark: Denial of Service via HTTP3 protocol dissector infinite loop
HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service
2026-01-14
Published