Wireshark disclosed CVE-2026-6528, a denial-of-service vulnerability in its TLS protocol dissector. Crafted TLS traffic can cause the dissector to enter an infinite loop, potentially hanging analysis sessions or consuming resources while affected packet captures or live traffic are processed.
The issue affects Wireshark versions 4.6.0 through 4.6.4 and is fixed in 4.6.5. The advisory, WNPA-SEC-2026-33, links the flaw to TLS Encrypted ClientHello (ECH) transcript handling and references upstream issues #21151 and #21147; organizations using affected versions should upgrade to 4.6.5 and avoid processing untrusted TLS captures until patched.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Wireshark published advisory WNPA-SEC-2026-33 for CVE-2026-6528, an infinite-loop condition in the TLS protocol dissector that can cause denial of service when processing affected TLS traffic. The issue affects versions 4.6.0 through 4.6.4 and is fixed in Wireshark 4.6.5.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
gitlab.com
Open sourcegitlab.com
Open sourcewireshark.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.