Wireshark disclosed a denial-of-service vulnerability in its BEEP protocol dissector that can crash the packet analyzer through a stack-call overflow caused by recursive function handling. The issue is tracked as CVE-2026-6538 and documented in advisory wnpa-sec-2026-23, with the underlying bug reported in Wireshark's issue tracker as a BEEP dissector stack-call overflow.
The flaw affects Wireshark versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14. According to the vendor, an attacker could trigger the crash by injecting a malformed packet onto the network or by convincing a user to open a crafted capture file. Wireshark said no active exploits are known, credited Sharon Brizinov with discovery, and released fixes in versions 4.6.5 and 4.4.15.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Wireshark disclosed a BEEP dissector crash vulnerability, CVE-2026-6538, affecting versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14. The advisory said malformed network packets or packet capture files could trigger a crash, credited Sharon Brizinov with discovery, noted no known exploits, and stated the issue was fixed in versions 4.6.5 and 4.4.15.
A GitLab issue was opened to track a stack-call overflow caused by a recursive function in Wireshark's BEEP dissector. This issue is referenced later by Wireshark's security advisory for CVE-2026-6538.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcewireshark.org
Open sourcegitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.