CVE-2026-15171
published 2026-07-08CVE-2026-15171: SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.10%
0.9th percentile
SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 4.4.0 < 4.4.17 | 4.4.17 |
| wireshark | wireshark | >= 4.6.0 < 4.6.7 | 4.6.7 |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.17 | 4.4.17 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.7 | 4.6.7 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GitLab
NULL Pointer Dereference in Wireshark
vendor_gitlab·2026-07-08·CVSS 5.5
CVE-2026-15171 [MEDIUM] CWE-476 NULL Pointer Dereference in Wireshark
NULL Pointer Dereference in Wireshark
SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.17 (affected)
Solution: Upgrade to version 4.6.7 or above
Credit: Dmitrijs Trizna
Red Hat
wireshark: Wireshark: Denial of service via SSH protocol dissector crash
vendor_redhat·2026-07-08·CVSS 5.5
CVE-2026-15171 [MEDIUM] CWE-1286 wireshark: Wireshark: Denial of service via SSH protocol dissector crash
wireshark: Wireshark: Denial of service via SSH protocol dissector crash
SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
A flaw was found in Wireshark's SSH (Secure Shell) protocol dissector. A remote attacker could craft a malicious network capture file that, when opened by a user, would cause the Wireshark application to crash. This vulnerability leads to a denial of service, preventing the user from analyzing network traffic.
Statement: Moderate: A denial of service flaw exists in Wireshark's SSH protocol dissector, where processing a specially crafted network capture file can lead to application termination. This issue requires user interaction to open a malicious file, limiting its impact to the availability of the Wireshark app
VulDB
Wireshark up to 4.4.16/4.6.6 SSH Protocol denial of service
vuldb·2026-07-08·CVSS 5.5
CVE-2026-15171 [MEDIUM] Wireshark up to 4.4.16/4.6.6 SSH Protocol denial of service
A vulnerability marked as problematic has been reported in Wireshark up to 4.4.16/4.6.6. The affected element is an unknown function of the component SSH Protocol. Performing a manipulation results in denial of service.
This vulnerability is identified as CVE-2026-15171. The attack can be initiated remotely. There is not any exploit available.
GHSA
SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
ghsa_unreviewed·2026-07-08
CVE-2026-15171 [MEDIUM] CWE-476 SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-15171 wireshark: Wireshark: Denial of service via SSH protocol dissector crash [fedora-all]
bugzilla·2026-07-09·CVSS 5.5
CVE-2026-15171 [MEDIUM] CVE-2026-15171 wireshark: Wireshark: Denial of service via SSH protocol dissector crash [fedora-all]
CVE-2026-15171 wireshark: Wireshark: Denial of service via SSH protocol dissector crash [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Bugzilla
CVE-2026-15171 wireshark: Wireshark: Denial of service via SSH protocol dissector crash
bugzilla·2026-07-08·CVSS 5.5
CVE-2026-15171 [MEDIUM] CVE-2026-15171 wireshark: Wireshark: Denial of service via SSH protocol dissector crash
CVE-2026-15171 wireshark: Wireshark: Denial of service via SSH protocol dissector crash
SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
2026-07-08
Published