Wireshark fixed CVE-2026-6526, a null-pointer dereference that allows a crafted RTSP packet or malicious capture file to crash Wireshark and TShark during protocol dissection. The flaw affects Wireshark versions 4.6.0 through 4.6.4 and is resolved in 4.6.5; Wireshark reported no known exploitation.
A malformed RTSP DESCRIBE request can cause HTTP Location target resolution to produce an empty base URL, after which unchecked use of strstr() results in a NULL+3 dereference in determine_http_location_target. The remediation validates the strstr() return value before it is incremented and dereferenced; related fixes were merged and backported, although maintainers said the supplied proof of concept does not affect the 4.4.x branch.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Wireshark published advisory wnpa-sec-2026-35 for CVE-2026-6526, a crash vulnerability affecting versions 4.6.0 through 4.6.4. It released version 4.6.5 as the fix, recommended upgrading, and stated it was unaware of exploitation; Alexandre de Oliveira was credited with discovery.
Wireshark resolved a NULL-pointer dereference in determine_http_location_target that crafted RTSP/SDP traffic or a capture file could trigger, crashing TShark or the Wireshark GUI. The fix added validation of the strstr() result before incrementing and dereferencing it, and was merged through merge request !24268 with related backports.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcegitlab.com
Open sourcewireshark.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.