Wireshark disclosed CVE-2026-6521, a flaw in its OpenFlow v5 protocol dissector that can enter infinite loops and drive excessive CPU consumption. The issue affects Wireshark versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14, and can be triggered either by injecting a malformed packet onto the network or by opening a specially crafted packet capture file.
The vendor said it is not aware of active exploitation and credited Sharon Brizinov with discovering the bug. Wireshark released fixes in versions 4.6.5 and 4.4.15, and linked the issue to internal trackers 21182 and 21188. The vulnerability is cataloged as CVE-2026-6521 in the CVE record.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Wireshark stated the CVE-2026-6521 flaw was fixed in versions 4.6.5 and 4.4.15 and recommended users upgrade to those releases or later. The issue was credited to Sharon Brizinov and linked to Wireshark issues 21182 and 21188.
On April 29, 2026, Wireshark published security notice wnpa-sec-2026-39 for CVE-2026-6521, an infinite-loop flaw in the OpenFlow v5 protocol dissector that can lead to excessive CPU consumption when processing malformed packets or packet capture files. Wireshark said affected versions include 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14, and that it was unaware of active exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.