CVE-2026-5409
published 2026-04-30CVE-2026-5409: Monero protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.14%
4.0th percentile
Monero protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | 4.4.0 – 4.4.14 | — |
| wireshark | wireshark | 4.6.0 – 4.6.4 | — |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.15 | 4.4.15 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.5 | 4.6.5 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jjwc-p294-59xw: Monero protocol dissector crash in Wireshark 4
ghsa_unreviewed·2026-04-30
CVE-2026-5409 [MEDIUM] CWE-674 GHSA-jjwc-p294-59xw: Monero protocol dissector crash in Wireshark 4
Monero protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
GitLab
Uncontrolled Recursion in Wireshark
vendor_gitlab·2026-04-30·CVSS 5.5
CVE-2026-5409 [MEDIUM] CWE-674 Uncontrolled Recursion in Wireshark
Uncontrolled Recursion in Wireshark
Monero protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.15 (affected)
Solution: Upgrade to version 4.6.5 or above
Credit: Brendan Coles
Red Hat
wireshark: Wireshark: Denial of service via Monero protocol dissector crash
vendor_redhat·2026-04-30·CVSS 5.5
CVE-2026-5409 [MEDIUM] CWE-825 wireshark: Wireshark: Denial of service via Monero protocol dissector crash
wireshark: Wireshark: Denial of service via Monero protocol dissector crash
A flaw was found in Wireshark. A remote attacker could exploit a vulnerability in the Monero protocol dissector, leading to a crash of the application. This could result in a denial of service (DoS) for users analyzing network traffic.
Mitigation: To mitigate this issue, users can disable the Monero protocol dissector in Wireshark. This prevents the vulnerable code from being executed when analyzing network traffic containing Monero protocol data.
To disable the dissector:
1. Open Wireshark.
2. Go to `Analyze` -> `Enabled Protocols...`.
3. In the `Enabled Protocols` dialog, uncheck the box next to `Monero`.
4. Click `OK`.
Alternatively, users can avoid opening untrusted network trace files. Disabling the dissecto
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-5409 wireshark: Wireshark: Denial of service via Monero protocol dissector crash [fedora-all]
bugzilla·2026-05-04·CVSS 5.5
CVE-2026-5409 [MEDIUM] CVE-2026-5409 wireshark: Wireshark: Denial of service via Monero protocol dissector crash [fedora-all]
CVE-2026-5409 wireshark: Wireshark: Denial of service via Monero protocol dissector crash [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-5409 wireshark: Wireshark: Denial of service via Monero protocol dissector crash
bugzilla·2026-04-30·CVSS 5.5
CVE-2026-5409 [MEDIUM] CVE-2026-5409 wireshark: Wireshark: Denial of service via Monero protocol dissector crash
CVE-2026-5409 wireshark: Wireshark: Denial of service via Monero protocol dissector crash
Monero protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
2026-04-30
Published