CVE-2026-5408
published 2026-04-30CVE-2026-5408: BT-DHT protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.14%
4.1th percentile
BT-DHT protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | 4.4.0 – 4.4.14 | — |
| wireshark | wireshark | 4.6.0 – 4.6.4 | — |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.15 | 4.4.15 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.5 | 4.6.5 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fv3g-cjhx-6p3x: BT-DHT protocol dissector crash in Wireshark 4
ghsa_unreviewed·2026-04-30
CVE-2026-5408 [MEDIUM] CWE-674 GHSA-fv3g-cjhx-6p3x: BT-DHT protocol dissector crash in Wireshark 4
BT-DHT protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
GitLab
Uncontrolled Recursion in Wireshark
vendor_gitlab·2026-04-30·CVSS 5.5
CVE-2026-5408 [MEDIUM] CWE-674 Uncontrolled Recursion in Wireshark
Uncontrolled Recursion in Wireshark
BT-DHT protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.15 (affected)
Solution: Upgrade to version 4.6.5 or above
Credit: Brendan Coles
Red Hat
wireshark: Wireshark: Denial of service via BT-DHT protocol dissector crash
vendor_redhat·2026-04-30·CVSS 5.5
CVE-2026-5408 [MEDIUM] CWE-617 wireshark: Wireshark: Denial of service via BT-DHT protocol dissector crash
wireshark: Wireshark: Denial of service via BT-DHT protocol dissector crash
A flaw was found in Wireshark. A remote attacker could exploit a vulnerability in the BT-DHT protocol dissector, leading to a crash. This denial of service (DoS) vulnerability could prevent the application from processing network traffic, impacting its availability.
Mitigation: To mitigate this vulnerability, avoid opening or analyzing network capture files from untrusted sources, especially those containing BT-DHT protocol traffic. Users should exercise caution when processing any unknown or suspicious network data with Wireshark.
Package: wireshark (Red Hat Enterprise Linux 10) - Fix deferred
Package: wireshark (Red Hat Enterprise Linux 6) - Fix deferred
Package: wireshark (Red Hat Enterprise Linux 7) - Fix
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-5408 wireshark: Wireshark: Denial of service via BT-DHT protocol dissector crash [fedora-all]
bugzilla·2026-05-04·CVSS 5.5
CVE-2026-5408 [MEDIUM] CVE-2026-5408 wireshark: Wireshark: Denial of service via BT-DHT protocol dissector crash [fedora-all]
CVE-2026-5408 wireshark: Wireshark: Denial of service via BT-DHT protocol dissector crash [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-5408 wireshark: Wireshark: Denial of service via BT-DHT protocol dissector crash
bugzilla·2026-04-30·CVSS 5.5
CVE-2026-5408 [MEDIUM] CVE-2026-5408 wireshark: Wireshark: Denial of service via BT-DHT protocol dissector crash
CVE-2026-5408 wireshark: Wireshark: Denial of service via BT-DHT protocol dissector crash
BT-DHT protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
2026-04-30
Published