CVE-2026-6526
published 2026-04-30CVE-2026-6526: RTSP protocol dissector crash in Wireshark 4.6.0 to 4.6.4
PriorityP417medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.12%
2.5th percentile
RTSP protocol dissector crash in Wireshark 4.6.0 to 4.6.4
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | 4.6.0 – 4.6.4 | — |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.5 | 4.6.5 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fjhx-652f-phq2: RTSP protocol dissector crash in Wireshark 4
ghsa_unreviewed·2026-04-30
CVE-2026-6526 [MEDIUM] CWE-476 GHSA-fjhx-652f-phq2: RTSP protocol dissector crash in Wireshark 4
RTSP protocol dissector crash in Wireshark 4.6.0 to 4.6.4
Red Hat
wireshark: Wireshark: Denial of Service due to RTSP protocol dissector crash
vendor_redhat·2026-04-30·CVSS 5.5
CVE-2026-6526 [MEDIUM] CWE-617 wireshark: Wireshark: Denial of Service due to RTSP protocol dissector crash
wireshark: Wireshark: Denial of Service due to RTSP protocol dissector crash
A flaw was found in Wireshark, a network protocol analyzer. By processing a specially crafted Real-Time Streaming Protocol (RTSP) packet, a remote attacker could cause the Wireshark application to crash, leading to a denial of service. This vulnerability affects the RTSP protocol dissector.
Mitigation: Users can reduce exposure by avoiding the analysis of untrusted network capture files or live network traffic from untrusted sources. To specifically prevent the vulnerable RTSP dissector from processing packets, it can be disabled within Wireshark's preferences. Navigate to 'Analyze' -> 'Enabled Protocols...' and uncheck the 'RTSP' protocol. Disabling this protocol may impact the ability to analyze legitimate RTS
GitLab
NULL Pointer Dereference in Wireshark
vendor_gitlab·2026-04-30·CVSS 5.5
CVE-2026-6526 [MEDIUM] CWE-476 NULL Pointer Dereference in Wireshark
NULL Pointer Dereference in Wireshark
RTSP protocol dissector crash in Wireshark 4.6.0 to 4.6.4
Affected products: Wireshark
Affected versions: >=4.6.0, <4.6.5 (affected)
Solution: Upgrade to version 4.6.5 or above
Credit: Alexandre de Oliveira
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-6526 wireshark: Wireshark: Denial of Service due to RTSP protocol dissector crash [fedora-all]
bugzilla·2026-05-04·CVSS 5.5
CVE-2026-6526 [MEDIUM] CVE-2026-6526 wireshark: Wireshark: Denial of Service due to RTSP protocol dissector crash [fedora-all]
CVE-2026-6526 wireshark: Wireshark: Denial of Service due to RTSP protocol dissector crash [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6526 wireshark: Wireshark: Denial of Service due to RTSP protocol dissector crash
bugzilla·2026-04-30·CVSS 5.5
CVE-2026-6526 [MEDIUM] CVE-2026-6526 wireshark: Wireshark: Denial of Service due to RTSP protocol dissector crash
CVE-2026-6526 wireshark: Wireshark: Denial of Service due to RTSP protocol dissector crash
RTSP protocol dissector crash in Wireshark 4.6.0 to 4.6.4
2026-04-30
Published