WebSocket Protocol Dissector Crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14
CVE-2026-6869

5.5MEDIUM

Key Information:

Vendor

Wireshark

Status
Vendor
CVE Published:
30 April 2026

What is CVE-2026-6869?

A flaw in the WebSocket protocol dissector within Wireshark versions 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 can lead to a crash, resulting in a denial of service. This vulnerability affects the tool’s ability to analyze network traffic, potentially disrupting network monitoring operations. Attackers could exploit this flaw by sending specially crafted WebSocket packets to the affected versions, causing the application to unexpectedly terminate, thereby impacting users and network administrators relying on Wireshark for security assessments.

Affected Version(s)

Wireshark 4.6.0 < 4.6.5

Wireshark 4.4.0 < 4.4.15

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alexandre de Oliveira
.