Wireshark disclosed wnpa-sec-2026-42 for an infinite loop vulnerability in its RPKI-Router protocol dissector, tracked as CVE-2026-6522. The flaw can be triggered by a malformed packet seen on the wire or by opening a malformed packet trace file, causing Wireshark to enter an infinite loop and consume excessive CPU resources, resulting in a crash or denial-of-service condition.
The issue affects Wireshark versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14. Wireshark said it is not aware of exploitation in the wild and credited Sharon Brizinov with discovering the bug. Users are advised to upgrade to 4.6.5, 4.4.15, or later to remediate the vulnerability.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2026-6522 was published, documenting a denial-of-service infinite loop in Wireshark's RPKI-Router protocol dissector. The record references Wireshark advisory WNPA-SEC-2026-42, affected versions 4.6.0-4.6.4 and 4.4.0-4.4.14, fixed versions 4.6.5 and 4.4.15, and credits Sharon Brizinov as the finder.
Wireshark stated the vulnerability was fixed in versions 4.6.5 and 4.4.15 or later. The advisory also noted that Sharon Brizinov discovered the issue and that Wireshark was unaware of exploitation in the wild.
Wireshark published security advisory wnpa-sec-2026-42 for CVE-2026-6522, an infinite loop vulnerability in the RPKI-Router protocol dissector. The flaw affects versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14, and Wireshark said malformed packets or trace files could cause excessive CPU consumption.
A GitLab issue was opened to track an infinite loop vulnerability in Wireshark's RPKI-RTR dissector, associated with crash/DoS behavior. The issue is referenced later by Wireshark advisory wnpa-sec-2026-42.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcewireshark.org
Open sourcegitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.