Denial of Service Vulnerability in Wireshark by The Wireshark Team
CVE-2026-6524

5.5MEDIUM

Key Information:

Vendor

Wireshark

Status
Vendor
CVE Published:
30 April 2026

What is CVE-2026-6524?

A vulnerability exists in Wireshark affecting versions 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14, which can lead to a denial of service. This issue involves a crash in the MySQL protocol dissector, potentially resulting in an application halt and disrupting network analysis activities. Users of affected versions should consider upgrading to the latest release to mitigate risks associated with this flaw.

Affected Version(s)

Wireshark 4.6.0 < 4.6.5

Wireshark 4.4.0 < 4.4.15

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alexandre de Oliveira
.