Wireshark disclosed wnpa-sec-2026-61 for multiple infinite-loop vulnerabilities in its protocol dissectors, warning that malformed traffic or crafted capture files could drive excessive CPU consumption during analysis. The affected components include the MIH, MPEG DSM-CC, eDonkey, and MEGACO dissectors, and the vendor said the flaws affect Wireshark 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16. Fixed releases are 4.6.7 and 4.4.17, and Wireshark said it was not aware of exploitation at disclosure time.
The bugs were uncovered by Wireshark's internal fuzzing pipeline, which repeatedly crashed tshark on malformed .pcap inputs. GitLab issue reports show one flaw in the MPEG DSM-CC dissector where parsing failed to advance offsets in a loop, and another in the eDonkey dissector where list parsing allowed offsets to move backward, both leading to aborts consistent with infinite-loop conditions; one issue was tracked as CVE-2026-15163. Wireshark's advisory says an attacker could trigger the condition either by injecting malformed packets onto a network or by convincing a user to open a malicious capture file.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
On July 8, 2026, Wireshark published security advisory WNPA-SEC-2026-61 for multiple protocol dissector infinite loops tracked as CVE-2026-15163. The notice said MIH, MPEG DSM-CC, eDonkey, and MEGACO dissectors were affected, fixed the issue in versions 4.6.7 and 4.4.17, and stated Wireshark was unaware of any exploits.
A Wireshark ASan Menagerie Fuzz job found that tshark crashed on fuzz-2026-06-07-14731326484.pcap after new_field_info() detected that edonkey.blob_length was repeatedly added without advancing the maximum start offset, indicating a possible infinite loop. The issue was tracked as GitLab issue 21330 and later assigned CVE-2026-15163.
A Wireshark ASan Menagerie Fuzz job found that tshark could abort while processing fuzz-2026-05-25-14532035511.pcap because repeated additions of mpeg_dsmcc.un_sess.rsrc_cfs_num did not advance the maximum start offset, indicating a possible infinite loop. The issue was tracked as GitLab issue 21277 and was later associated with CVE-2026-15163.
Wireshark closed issue 21330 through merge request !25304, with related merged fixes !25305 and !25306, all titled "eDonkey: Don't let the offset go backwards when dissecting a list." The content does not provide an explicit date for the merge or closure event.
Wireshark closed issue 21277 after merging merge request !25094, with related merged fixes !25097 and !25098, all titled "MPEG DSM-CC: Advance the offset in a loop." The supplied content does not explicitly anchor the merge or closure to a calendar date.
Wireshark's July 2026 advisory states that multiple infinite-loop flaws affected the MIH, MPEG DSM-CC, eDonkey, and MEGACO dissectors, and references issue 21275 among the tracked bugs. No explicit date for the underlying 21275/21383 discovery event is provided in the supplied content.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
wireshark.org
Open sourcegitlab.com
Open sourcegitlab.com
Open sourcegitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.