Denial of Service Vulnerability in Wireshark by the Vendor Wireshark
CVE-2026-5401

5.5MEDIUM

Key Information:

Vendor

Wireshark

Status
Vendor
CVE Published:
30 April 2026

What is CVE-2026-5401?

A vulnerability exists in Wireshark versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14 that could lead to a denial of service. The issue arises when the AFP Spotlight protocol dissector crashes, causing the application to become unresponsive or terminate unexpectedly. Network analysis workflows could be disrupted, impacting users who rely on Wireshark for security monitoring or troubleshooting. Users are advised to upgrade to the latest version to mitigate these risks.

Affected Version(s)

Wireshark 4.6.0 < 4.6.5

Wireshark 4.4.0 < 4.4.15

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Brendan Coles
.