Wireshark disclosed CVE-2026-0960, an infinite-loop flaw in its HTTP/3 dissector that can be triggered when the application decrypts traffic in a crafted packet-capture file. Opening such a PCAPNG capture can cause Wireshark to hang and consume excessive CPU resources, creating a denial-of-service risk for analysts.
The issue affects Wireshark versions 4.6.0 through 4.6.2 and 4.4.0 through 4.4.12. Wireshark fixed the vulnerability in versions 4.6.3 and 4.4.13; the vendor reported no known exploitation when it published the advisory.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Wireshark published advisory wnpa-sec-2026-04 for CVE-2026-0960, an HTTP/3 dissector infinite loop that can cause excessive CPU use when a user opens a malformed trace file. The issue affects versions 4.6.0–4.6.2 and 4.4.0–4.4.12 and was fixed in versions 4.6.3 and 4.4.13; Wireshark said it knew of no exploitation.
Tom Needham reported Wireshark issue 20944, describing a hang when Wireshark loads and decrypts a PCAPNG capture file.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.