CVE-2026-15173
published 2026-07-08CVE-2026-15173: pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
PriorityP416medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.09%
0.5th percentile
pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 4.6.0 < 4.6.7 | 4.6.7 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.7 | 4.6.7 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GitLab
Heap-based Buffer Overflow in Wireshark
vendor_gitlab·2026-07-08·CVSS 4.7
CVE-2026-15173 [MEDIUM] CWE-122 Heap-based Buffer Overflow in Wireshark
Heap-based Buffer Overflow in Wireshark
pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, <4.6.7 (affected)
Solution: Upgrade to version 4.6.7 or above
Credit: Mitchell Benjamin
Red Hat
Wireshark: Wireshark: Denial of Service via pcapng file parser crash
vendor_redhat·2026-07-08·CVSS 5.5
CVE-2026-15173 [MEDIUM] CWE-825 Wireshark: Wireshark: Denial of Service via pcapng file parser crash
Wireshark: Wireshark: Denial of Service via pcapng file parser crash
pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
A flaw was found in Wireshark. A remote attacker could exploit a vulnerability in the pcapng file parser, leading to a crash of the application. This denial of service (DoS) could prevent legitimate users from accessing the service, impacting its availability.
Statement: This Moderate impact denial of service flaw in Wireshark's pcapng file parser can be triggered when processing a specially crafted capture file. An attacker could provide a malicious pcapng file, leading to an application crash and preventing legitimate network analysis. Exploitation requires user interaction, as the user must open the malicious file.
Mitigation: To mitigate
VulDB
Wireshark up to 4.6.6 pcapng File Parser denial of service
vuldb·2026-07-09·CVSS 4.7
CVE-2026-15173 [MEDIUM] Wireshark up to 4.6.6 pcapng File Parser denial of service
A vulnerability classified as problematic has been found in Wireshark up to 4.6.6. This affects an unknown function of the component pcapng File Parser. The manipulation leads to denial of service.
This vulnerability is listed as CVE-2026-15173. The attack may be initiated remotely. There is no available exploit.
GHSA
pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
ghsa_unreviewed·2026-07-08
CVE-2026-15173 [MEDIUM] CWE-122 pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-15173 wireshark: Wireshark: Denial of Service via pcapng file parser crash [fedora-all]
bugzilla·2026-07-09·CVSS 5.5
CVE-2026-15173 [MEDIUM] CVE-2026-15173 wireshark: Wireshark: Denial of Service via pcapng file parser crash [fedora-all]
CVE-2026-15173 wireshark: Wireshark: Denial of Service via pcapng file parser crash [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
Bugzilla
CVE-2026-15173 Wireshark: Wireshark: Denial of Service via pcapng file parser crash
bugzilla·2026-07-08·CVSS 5.5
CVE-2026-15173 [MEDIUM] CVE-2026-15173 Wireshark: Wireshark: Denial of Service via pcapng file parser crash
CVE-2026-15173 Wireshark: Wireshark: Denial of Service via pcapng file parser crash
pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
2026-07-08
Published