Heap Overflow Vulnerability in Wireshark TLS Protocol Dissector
CVE-2026-5402

8.8HIGH

Key Information:

Vendor

Wireshark

Status
Vendor
CVE Published:
30 April 2026

What is CVE-2026-5402?

A heap overflow vulnerability has been identified in the TLS protocol dissector component of Wireshark, affecting versions 4.6.0 to 4.6.4. This flaw can lead to a denial of service and may provide an opportunity for malicious code execution. Attackers can exploit this vulnerability by crafting specific packets that trigger the overflow, potentially compromising system integrity. Users are advised to update to the latest version of Wireshark to mitigate this risk.

Affected Version(s)

Wireshark 4.6.0 < 4.6.5

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Duc Anh Nguyen
.