Wireshark fixed CVE-2026-3202, a denial-of-service flaw in its NTS-KE protocol dissector that can crash Wireshark or Tshark when processing malformed NTS-KE network traffic or crafted packet-capture files. The vulnerability affects Wireshark versions 4.6.0 through 4.6.3; Wireshark reported no known exploitation in the wild.
The defect was discovered by ASan Menagerie fuzzing, which triggered a null-pointer read in strcmp from dissect_nts_ke while Tshark analyzed TLS-carried NTS-KE traffic. The remediation adds a presence check for the ALPN string before comparison; it was merged in merge request !23512 and commit 5fdfc578. Organizations using affected releases should upgrade to Wireshark 4.6.4 or later.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Wireshark published advisory wnpa-sec-2026-06 for CVE-2026-3202, a denial-of-service flaw affecting versions 4.6.0 through 4.6.3. Malformed NTS-KE network traffic or packet-trace files could crash Wireshark; version 4.6.4 resolves the issue, and Wireshark reported no known exploitation.
Wireshark's ASan Menagerie fuzzing job detected a null-pointer read crash in the NTS-KE dissector while processing a malformed capture file. The crash reached strcmp from dissect_nts_ke while Tshark processed TLS-carried NTS-KE traffic.
Wireshark corrected the NTS-KE dissector to verify that an ALPN string is present before calling strcmp. The fix was merged in merge request !23512 and the issue was closed with commit 5fdfc578.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.