Wireshark Foundation Wireshark vulnerabilities
138 known vulnerabilities affecting wireshark_foundation/wireshark.
Total CVEs
138
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH58MEDIUM78LOW1
Vulnerabilities
Page 7 of 7
CVE-2026-5299P4MEDIUMCVSS 5.5≥ 4.6.0, < 4.6.5≥ 4.4.0, < 4.4.152026-04-30
CVE-2026-5299 [MEDIUM] CWE-674 CVE-2026-5299: ICMPv6 PvD protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of
ICMPv6 PvD protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
nvd
CVE-2026-5401P4MEDIUMCVSS 5.5≥ 4.6.0, < 4.6.5≥ 4.4.0, < 4.4.152026-04-30
CVE-2026-5401 [MEDIUM] CWE-674 CVE-2026-5401: AFP Spotlight protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial
AFP Spotlight protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
nvd
CVE-2025-13499P4MEDIUMCVSS 5.5v4.6.0≥ 4.4.0, < 4.4.112025-11-21
CVE-2025-13499 [MEDIUM] CWE-824 CVE-2025-13499: Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service
Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service
nvd
CVE-2025-11626P4MEDIUMCVSS 5.5≥ 4.4.0, < 4.4.10≥ 4.2.0, < 4.2.142025-10-10
CVE-2025-11626 [MEDIUM] CWE-835 CVE-2025-11626: MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of servi
MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service
nvd
CVE-2026-15174P4MEDIUMCVSS 5.5≥ 4.6.0, < 4.6.7≥ 4.4.0, < 4.4.172026-07-08
CVE-2026-15174 [MEDIUM] CWE-122 CVE-2026-15174: Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows den
Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
nvd
CVE-2023-3648P4MEDIUMCVSS 5.5≥ 4.0.0, < 4.0.7≥ 3.6.0, < 3.6.152023-07-14
CVE-2023-3648 [MEDIUM] CWE-762 CVE-2023-3648: Kafka dissector crash in Wireshark 4.0.0 to 4.0.6 and 3.6.0 to 3.6.14 allows denial of service via p
Kafka dissector crash in Wireshark 4.0.0 to 4.0.6 and 3.6.0 to 3.6.14 allows denial of service via packet injection or crafted capture file
nvd
CVE-2024-8645P4MEDIUMCVSS 5.5≥ 4.2.0, < 4.2.6≥ 4.0.0, < 4.0.162024-09-10
CVE-2024-8645 [MEDIUM] CWE-824 CVE-2024-8645: SPRT dissector crash in Wireshark 4.2.0 to 4.0.5 and 4.0.0 to 4.0.15 allows denial of service via pa
SPRT dissector crash in Wireshark 4.2.0 to 4.0.5 and 4.0.0 to 4.0.15 allows denial of service via packet injection or crafted capture file
nvd
CVE-2026-6529P4MEDIUMCVSS 5.5≥ 4.6.0, < 4.6.5≥ 4.4.0, < 4.4.152026-04-30
CVE-2026-6529 [MEDIUM] CWE-122 CVE-2026-6529: iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
nvd
CVE-2026-6526P4MEDIUMCVSS 5.5≥ 4.6.0, < 4.6.52026-04-30
CVE-2026-6526 [MEDIUM] CWE-476 CVE-2026-6526: RTSP protocol dissector crash in Wireshark 4.6.0 to 4.6.4
RTSP protocol dissector crash in Wireshark 4.6.0 to 4.6.4
nvd
CVE-2026-0960P4MEDIUMCVSS 5.5≥ 4.6.0, < 4.6.32026-01-14
CVE-2026-0960 [MEDIUM] CWE-835 CVE-2026-0960: HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service
HTTP3 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.2 allows denial of service
nvd
CVE-2026-5404P4MEDIUMCVSS 5.5≥ 4.6.0, < 4.6.5≥ 4.4.0, < 4.4.152026-05-01
CVE-2026-5404 [MEDIUM] CWE-120 CVE-2026-5404: K12 RF5 file parser crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
K12 RF5 file parser crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
nvd
CVE-2026-9759P4MEDIUMCVSS 5.5≥ 4.6.0, < 4.6.6≥ 4.4.0, < 4.4.162026-05-27
CVE-2026-9759 [MEDIUM] CWE-476 CVE-2026-9759: ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of servi
ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service
nvd
CVE-2022-4344P4MEDIUMCVSS 4.3v>=4.0.0, <4.0.2v>=3.6.0, <3.6.102023-01-12
CVE-2022-4344 [MEDIUM] CWE-400 CVE-2022-4344: Memory exhaustion in the Kafka protocol dissector in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 all
Memory exhaustion in the Kafka protocol dissector in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of service via packet injection or crafted capture file
nvd
CVE-2026-15165P4MEDIUMCVSS 5.5≥ 4.6.0, < 4.6.72026-07-08
CVE-2026-15165 [MEDIUM] CWE-122 CVE-2026-15165: TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
nvd
CVE-2025-13945P4MEDIUMCVSS 5.5≥ 4.6.0, < 4.6.12025-12-03
CVE-2025-13945 [MEDIUM] CWE-1325 CVE-2025-13945: HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service
HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service
nvd
CVE-2025-13674P4MEDIUMCVSS 5.5v4.6.02025-11-26
CVE-2025-13674 [MEDIUM] CWE-824 CVE-2025-13674: BPv7 dissector crash in Wireshark 4.6.0 allows denial of service
BPv7 dissector crash in Wireshark 4.6.0 allows denial of service
nvd
CVE-2026-15173P4MEDIUMCVSS 5.5≥ 4.6.0, < 4.6.72026-07-08
CVE-2026-15173 [MEDIUM] CWE-122 CVE-2026-15173: pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
nvd
CVE-2026-15168P4LOWCVSS 3.3≥ 4.6.0, < 4.6.7≥ 4.4.0, < 4.4.172026-07-08
CVE-2026-15168 [LOW] CWE-457 CVE-2026-15168: BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows possible information disclosu
BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows possible information disclosure
nvd
← Previous7 / 7