Wireshark disclosed and patched a broad set of vulnerabilities across its packet analysis engine, protocol dissectors, codecs, decompression routines, and the sharkd backend, with the most serious issues including possible code execution, memory corruption, and denial of service. The release notes for Wireshark 4.6.6 aggregate advisories wnpa-sec-2026-08 through wnpa-sec-2026-50, while earlier coordinated fixes shipped in 4.6.5 and 4.4.15 for affected 4.6.0-4.6.4 and 4.4.0-4.4.14 branches. One high-severity flaw, tracked as CVE-2026-5656, allowed a crafted configuration-profile ZIP to escape the intended extraction path and plant a Lua plugin for execution on the next launch. Additional issues included crashes and memory-safety bugs in AMR-NB (CVE-2026-5654), iLBC (CVE-2026-5657), ASN.1 PER (CVE-2026-6527), DCP-ETSI (CVE-2026-5653, CVE-2026-6530), and later sharkd and Bluetooth AVRCP flaws that could crash the process or potentially enable control-flow hijack.
Several vulnerabilities were reachable simply by opening a malicious packet capture or by parsing malformed traffic on the wire. Wireshark documented infinite-loop and CPU-exhaustion conditions in the USB HID dissector (CVE-2026-6534), OpenFlow v5 dissector (CVE-2026-6521), and LZ77 decompression path (CVE-2026-6533), alongside crashes in BEEP (CVE-2026-6538) and other protocol handlers. GitLab issue reports show researchers and fuzzing jobs repeatedly triggering heap overflows, double-free conditions, NULL dereferences, and non-advancing-offset parser failures in components such as DCP-ETSI, H.245, MIH, eDonkey, and sharkd, underscoring that malformed captures can destabilize both the GUI and tshark. Wireshark said it was not aware of active exploitation at disclosure time and urged users to update to the fixed releases.

See real exploitation activity before you spend the cycle.
19 events from the most recent confirmed update back to the earliest known activity.
Wireshark's GitLab issue #21488 documented the AVRCP vendor-dependent fragment reassembly flaw and said it was assigned CVE-2026-76917. The report described crashes in stock Wireshark and ASan-confirmed heap overflow behavior.
A heap-based buffer overflow in Wireshark's Bluetooth AVRCP dissector was discovered when fragment reassembly length accumulation could wrap a 32-bit integer and lead to an undersized allocation followed by a large memcpy. The report states the issue was discovered on August 7, 2026.
GitLab issue #21447 reported a NULL pointer dereference in the H.245 dissector when nested GenericMessage handling cleared packet state and later wrote through a NULL pointer. The issue was assigned CVE-2026-76927.
GitLab issue #21395 reported a stack-use-after-return in sharkd caused by leaving a global tap listener pointing to a stack-local RTP tap object after an error path. The issue was later assigned CVE-2026-76891.
A second ASan Menagerie Fuzz CI job found a tshark crash where repeated additions of edonkey.blob_length did not advance the maximum start offset, indicating another possible infinite loop. This issue was also assigned CVE-2026-15163.
An ASan Menagerie Fuzz CI job found a tshark crash caused by repeated non-advancing additions of the MIH field mih.cos_id, indicating a possible infinite loop. The issue was later assigned CVE-2026-15163.
On April 29, 2026, Wireshark published a coordinated batch of advisories including wnpa-sec-2026-18, -20, -22, -23, -27, -28, -31, -34, and -39, covering AMR-NB, iLBC, DCP-ETSI, BEEP, USB HID, LZ77, ASN.1 PER, and OpenFlow v5 flaws. Wireshark said the issues were fixed in versions 4.6.5 and 4.4.15.
GitLab issue #21188 reported a second OpenFlow v5 infinite-loop flaw in tablemod property parsing when malformed properties prevented offset advancement. This issue was also assigned CVE-2026-6521.
GitLab issue #21182 reported that malformed unknown actions in the OpenFlow v5 dissector could reset offsets and trap Wireshark in an infinite loop. The issue was later tracked under CVE-2026-6521.
GitLab issue #21149 reported a crash condition in Wireshark dissectors using ASN.1 PER encoding due to missing recursion depth limits. The issue was later assigned CVE-2026-6527.
Wireshark opened issue #21130 to coordinate release notes, advisories, and CVE requests for a large batch of vulnerabilities planned for versions 4.6.5 and 4.4.15. The tracker covered crashes, infinite loops, memory corruption, and the profile import RCE path traversal flaw.
GitLab issue #21144 documented a heap buffer overflow in Wireshark's DCP-ETSI PFT rs_deinterleave logic. The issue was later assigned CVE-2026-6530.
GitLab issue #21121 reported that a crafted USB HID report descriptor could drive Wireshark's USB HID dissector into an unbounded loop, causing CPU and memory exhaustion. The issue was later assigned CVE-2026-6534.
A second DCP-ETSI heap buffer overflow affecting rs_deinterleave was validated against Wireshark 4.7.0 at HEAD commit db3e7964fd. The report described a distinct Reed-Solomon-related bug that could potentially enable arbitrary code execution.
GitLab issue #21122 reported a heap buffer overflow in Wireshark's DCP-ETSI PFT Reed-Solomon error-correction path that could be triggered by opening a crafted PCAP. The issue was later assigned CVE-2026-5653.
Wireshark's GitLab issue #21115 documented a Zip-Slip path traversal flaw in Configuration Profile import that could lead to code execution by planting a Lua plugin outside the intended extraction directory. The report confirmed the issue in Wireshark 4.6.4 and on the master branch.
GitLab issue #21113 reported an iLBC audio codec double-free in Wireshark caused by freeing the wrong target. The issue was later assigned CVE-2026-5657.
GitLab issue #21111 reported a stack buffer overflow in Wireshark's AMR-NB bandwidth-efficient codec decoder. This issue was later tracked as CVE-2026-5654.
Wireshark 4.6.6 release notes disclosed a large set of advisories from wnpa-sec-2026-08 through wnpa-sec-2026-50, covering numerous dissector, codec, decompression, Sharkd, and parser vulnerabilities including possible code execution cases. The release notes tied the issues to many CVEs across protocols such as TLS, RDP, SMB2, HTTP, WebSocket, ZigBee, OpenFlow, and MySQL.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
33 references tracked. Mallory keeps watching after this page renders.
gitlab.com
Open sourcegitlab.com
Open sourcegitlab.com
Open sourcegitlab.com
Open sourcegitlab.com
Open sourcewireshark.org
Open sourcewireshark.org
Open sourcewireshark.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.