Denial of Service Vulnerability in Wireshark by Riverbed Technology
CVE-2026-6533

5.5MEDIUM

Key Information:

Vendor

Wireshark

Status
Vendor
CVE Published:
30 April 2026

What is CVE-2026-6533?

A flaw in the LZ77 decompression engine of Wireshark versions 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 causes the application to crash when processing certain inputs. This vulnerability can be exploited to create a denial of service condition, effectively disrupting the functionality of the network analysis tool. Users of affected versions are recommended to upgrade to the latest version immediately to mitigate risks associated with this issue.

Affected Version(s)

Wireshark 4.6.0 < 4.6.5

Wireshark 4.4.9 < 4.4.15

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sharon Brizinov
.