Wireshark disclosed CVE-2026-5407, an infinite-loop denial-of-service flaw in its SMB2 protocol dissector that can cause the application to consume excessive CPU resources when processing a malformed network packet or a crafted packet capture file. The issue was documented in a GitLab report and later published by Wireshark as advisory wnpa-sec-2026-11.
The vulnerability affects Wireshark versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14. Wireshark said the flaw was fixed in versions 4.6.5 and 4.4.15, and reported that no exploits were known at the time of disclosure. Organizations that use Wireshark for packet analysis should update affected installations to the patched releases to prevent malformed SMB2 traffic or capture files from locking the tool into an infinite loop.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Wireshark published advisory wnpa-sec-2026-11 for an SMB2 dissector infinite loop vulnerability, tracked as CVE-2026-5407, affecting versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14. The company said malformed network packets or packet capture files could trigger excessive CPU consumption and fixed the issue in versions 4.6.5 and 4.4.15, with no known exploits at disclosure.
A GitLab issue was created to track an SMB2 dissector infinite loop denial-of-service bug in Wireshark. This issue is referenced by Wireshark's later security advisory for CVE-2026-5407.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcewireshark.org
Open sourcegitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.