Denial of Service Vulnerability in Wireshark by the Vendor
CVE-2026-5405

7.8HIGH

Key Information:

Vendor

Wireshark

Status
Vendor
CVE Published:
30 April 2026

What is CVE-2026-5405?

A denial of service vulnerability exists in the RDP protocol dissector of Wireshark, affecting versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14. Exploiting this flaw can lead to a crash of the application, which may allow malicious users to potentially execute arbitrary code on the affected system. Users are advised to update to the latest version of Wireshark to mitigate this risk.

Affected Version(s)

Wireshark 4.6.0 < 4.6.5

Wireshark 4.4.0 < 4.4.15

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Duc Anh Nguyen
.