Wireshark disclosed CVE-2026-15171, a denial-of-service flaw in the SSH protocol dissector that can crash the application when a user opens a specially crafted pcapng trace file. The bug stems from a NULL pointer dereference in ssh_keylog_process_line() while parsing a malformed SSH Decryption Secrets Block, where empty or oversized hex tokens can cause ssh_kex_make_bignum() to return NULL and then be dereferenced.
The issue affects workflows that process untrusted capture files with embedded SSH decryption metadata, including the Wireshark GUI, tshark, and sharkd, but it is not triggered by malicious SSH network traffic alone because the attacker-controlled input must be in pcapng metadata. Wireshark said the flaw affects versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16, with fixes released in 4.6.7 and 4.4.17; the bug was reproduced with AddressSanitizer via OSS-Fuzz, and no active exploits were known at disclosure time.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Wireshark stated that CVE-2026-15171 was fixed in versions 4.6.7 and 4.4.17, with affected ranges listed as 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16. Users were advised to upgrade to the fixed releases or later.
On July 8, 2026, Wireshark published security advisory wnpa-sec-2026-55 for CVE-2026-15171, describing an SSH protocol dissector crash that could be triggered by persuading a user to open a malformed packet trace file. The advisory credited Aisle Research and stated that no exploits were known.
Aisle Research reported that Wireshark could crash with a NULL pointer dereference in `ssh_keylog_process_line()` when opening a crafted pcapng file containing malformed SSH Decryption Secrets metadata. The issue affected workflows such as the Wireshark GUI, `tshark`, and `sharkd`, and was characterized as a denial-of-service condition rather than remote code execution.
Wireshark merged fix-related merge requests `!25557`, `!25561`, and `!25562`, and the issue activity states the bug was closed with commit `97421ea7`. The project also assigned CVE-2026-15171 to the vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
wireshark.org
Open sourcegitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.