CVE-2026-6869
published 2026-04-30CVE-2026-6869: WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.13%
2.6th percentile
WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | 4.4.0 – 4.4.14 | — |
| wireshark | wireshark | 4.6.0 – 4.6.4 | — |
| wireshark_foundation | wireshark | >= 4.4.0 < 4.4.15 | 4.4.15 |
| wireshark_foundation | wireshark | >= 4.6.0 < 4.6.5 | 4.6.5 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Wireshark up to 4.4.14/4.6.4 WebSocket Protocol Dissector improperly controlled sequential memory allocation (WID-SEC-2026-1311)
vuldb·2026-05-01·CVSS 5.5
CVE-2026-6869 [MEDIUM] Wireshark up to 4.4.14/4.6.4 WebSocket Protocol Dissector improperly controlled sequential memory allocation (WID-SEC-2026-1311)
A vulnerability marked as problematic has been reported in Wireshark up to 4.4.14/4.6.4. This issue affects some unknown processing of the component WebSocket Protocol Dissector. The manipulation leads to improperly controlled sequential memory allocation.
This vulnerability is uniquely identified as CVE-2026-6869. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
GHSA
GHSA-56rm-3mr5-jfrm: WebSocket protocol dissector crash in Wireshark 4
ghsa_unreviewed·2026-04-30
CVE-2026-6869 [MEDIUM] CWE-1325 GHSA-56rm-3mr5-jfrm: WebSocket protocol dissector crash in Wireshark 4
WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
GitLab
Improperly Controlled Sequential Memory Allocation in Wireshark
vendor_gitlab·2026-04-30·CVSS 5.5
CVE-2026-6869 [MEDIUM] CWE-1325 Improperly Controlled Sequential Memory Allocation in Wireshark
Improperly Controlled Sequential Memory Allocation in Wireshark
WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Affected products: Wireshark
Affected versions: >=4.6.0, =4.4.0, <4.4.15 (affected)
Solution: Upgrade to version 4.6.5 or above
Credit: Alexandre de Oliveira
Red Hat
wireshark: Wireshark: Denial of Service via WebSocket protocol dissector crash
vendor_redhat·2026-04-30·CVSS 5.5
CVE-2026-6869 [MEDIUM] CWE-237 wireshark: Wireshark: Denial of Service via WebSocket protocol dissector crash
wireshark: Wireshark: Denial of Service via WebSocket protocol dissector crash
A flaw was found in Wireshark. A remote attacker could exploit a vulnerability in the WebSocket protocol dissector, causing a crash. This could lead to a denial of service (DoS) condition, making the application unavailable to legitimate users.
Mitigation: To mitigate this issue, users should avoid opening untrusted capture files or performing live captures on untrusted networks with Wireshark. Limiting Wireshark's exposure to only trusted network traffic can reduce the risk of exploitation.
Package: wireshark (Red Hat Enterprise Linux 10) - Fix deferred
Package: wireshark (Red Hat Enterprise Linux 6) - Fix deferred
Package: wireshark (Red Hat Enterprise Linux 7) - Fix deferred
Package: wireshark (Red Hat
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-6869 wireshark: Wireshark: Denial of Service via WebSocket protocol dissector crash [fedora-all]
bugzilla·2026-05-04·CVSS 5.5
CVE-2026-6869 [MEDIUM] CVE-2026-6869 wireshark: Wireshark: Denial of Service via WebSocket protocol dissector crash [fedora-all]
CVE-2026-6869 wireshark: Wireshark: Denial of Service via WebSocket protocol dissector crash [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6869 wireshark: Wireshark: Denial of Service via WebSocket protocol dissector crash
bugzilla·2026-04-30·CVSS 5.5
CVE-2026-6869 [MEDIUM] CVE-2026-6869 wireshark: Wireshark: Denial of Service via WebSocket protocol dissector crash
CVE-2026-6869 wireshark: Wireshark: Denial of Service via WebSocket protocol dissector crash
WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
2026-04-30
Published