Wireshark disclosed CVE-2026-6533, a flaw in its dissection engine that can cause the application to crash or consume excessive CPU resources when processing malformed LZ77-compressed data. The issue was reported as an SMB2 LZ77 decompression bomb and can be triggered either by a crafted packet seen on the wire or by opening a malicious packet capture file, resulting in a denial-of-service condition for analysts using the tool.
The vulnerability affects Wireshark versions 4.6.0 through 4.6.4 and 4.4.9 through 4.4.14. Wireshark fixed the bug in versions 4.6.5 and 4.4.15, and credited Sharon Brizinov with the discovery. The project said no active exploits were known at the time of disclosure, but organizations that rely on Wireshark for packet analysis should update affected installations to the patched releases.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Wireshark published security advisory wnpa-sec-2026-28 for CVE-2026-6533, describing an LZ77 decompression crash in the dissection engine that could be triggered by malformed packets or trace files and could also cause excessive CPU consumption. The advisory says the issue affects versions 4.6.0 through 4.6.4 and 4.4.9 through 4.4.14, was discovered by Sharon Brizinov, and was fixed in versions 4.6.5 and 4.4.15.
A GitLab issue titled "SMB2 LZ77 Decompression Bomb (crash/dos)" was opened as issue #21127, documenting the underlying problem later tied to the Wireshark vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcewireshark.org
Open sourcegitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.