Wireshark disclosed CVE-2026-5653, a heap-based buffer overflow in its DCP-ETSI protocol dissector that can crash the network protocol analyzer and cause a denial of service. The flaw affects Wireshark versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14, and was assigned CWE-122 with a CVSS v3.1 score of 5.5.
According to the advisory, an attacker could trigger the issue by injecting a malformed packet onto the network or by convincing a user to open a crafted packet capture file. Wireshark fixed the vulnerability in versions 4.6.5 and 4.4.15; the issue was discovered by Alexandre de Oliveira, and the vendor said no active exploits were known at the time of disclosure.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2026-5653 was published, describing the Wireshark DCP-ETSI issue as a heap-based buffer overflow that can cause denial of service by crashing the application. The record credits Alexandre de Oliveira, references WNPA-SEC-2026-22 and issue 21122, and lists fixed versions 4.6.5 and 4.4.15.
Wireshark published advisory WNPA-SEC-2026-22 for CVE-2026-5653, a DCP-ETSI dissector flaw that can crash Wireshark when processing malformed network traffic or packet capture files. The advisory says affected versions are 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14, and that the issue was fixed in versions 4.6.5 and 4.4.15.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.