CVE-2026-5656
published 2026-05-01CVE-2026-5656: Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution
PriorityP337high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.18%
7.8th percentile
Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 4.4.0 < 4.4.15 | 4.4.15 |
| wireshark | wireshark | >= 4.6.0 < 4.6.5 | 4.6.5 |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.15 | 4.4.15 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.5 | 4.6.5 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GitLab
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark
vendor_gitlab·2026-04-30·CVSS 7.0
CVE-2026-5656 [HIGH] CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark
Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.15 (affected)
Solution: Upgrade to version 4.6.5 or above
Credit: TODO
Red Hat
wireshark: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark
vendor_redhat·2026-04-30·CVSS 7.8
CVE-2026-5656 [HIGH] CWE-22 wireshark: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark
wireshark: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark
A flaw was found in Wireshark. A path traversal can occur when a malformed configuration profile is imported, resulting in a denial of service or potentially in code execution.
Statement: This issue will cause a crash in Wireshark and potentially result in code execution. This flaw can only be exploited when a malformed malformed configuration profile is imported. Due to these reasons, this vulnerability has been rated with an important severity.
Mitigation: To mitigate this flaw, do not import configuration profiles from untrusted or unverified sources.
Package: wireshark (Red Hat Enterprise Linux 10) - Affected
Package: wireshark (Red Hat Enterprise Linux 6) - Not affected
Package
GHSA
GHSA-fw82-f2cv-p6p2: Profile import path traversal in Wireshark 4
ghsa_unreviewed·2026-05-01
CVE-2026-5656 [HIGH] CWE-22 GHSA-fw82-f2cv-p6p2: Profile import path traversal in Wireshark 4
Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-5656 wireshark: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark [fedora-all]
bugzilla·2026-05-04·CVSS 7.8
CVE-2026-5656 [HIGH] CVE-2026-5656 wireshark: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark [fedora-all]
CVE-2026-5656 wireshark: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-5656 wireshark: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark
bugzilla·2026-05-01·CVSS 7.8
CVE-2026-5656 [HIGH] CVE-2026-5656 wireshark: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark
CVE-2026-5656 wireshark: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark
Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution
Hackernews
⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More
blogs_hackernews·2026-05-04·CVSS 9.3
CVE-2026-41940 [CRITICAL] ⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More
This week, the shadows moved faster than the patches.
While most teams were still triaging last month’s alerts, attackers had already turned control panels into kill switches, kernels into open doors, and open-source pipelines into silent delivery systems.
The game has shifted from breach to occupation. They’re living inside SaaS sessions, pushing code with trusted commits, and scaling operations like legitimate businesses — except their product is chaos. And the underground is getting uncomfortably professional.
Here’s the full week
https://gitlab.com/wireshark/wireshark/-/issues/21115https://www.wireshark.org/security/wnpa-sec-2026-21.htmlhttps://access.redhat.com/errata/RHSA-2026:20600https://access.redhat.com/errata/RHSA-2026:26182https://access.redhat.com/security/cve/CVE-2026-5656https://bugzilla.redhat.com/show_bug.cgi?id=2464276https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5656.json
2026-05-01
Published