Wireshark disclosed CVE-2026-15165, a flaw in TLS Encrypted Client Hello (ECH) transcript reconstruction affecting versions 4.6.0 through 4.6.6. A specially crafted packet capture containing repeated ech_outer_extensions entries can trigger a heap-based buffer overflow when Wireshark or tshark decrypts and processes the embedded TLS data, causing the application to crash when the capture is opened.
The proof of concept uses a Decryption Secrets Block in the capture to provide the HPKE secret needed to decrypt and validate the malicious inner ClientHello, removing the need for separate victim-side decryption configuration. The reported overflow can write attacker-controlled data beyond the allocated buffer and may present memory-corruption and potential code-execution risk, although Wireshark said no exploitation is known. Wireshark fixed the issue in version 4.6.7; organizations should upgrade analysis workstations and automated tshark processing environments.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Wireshark issued advisory WNPA-SEC-2026-56 for CVE-2026-15165, affecting versions 4.6.0 through 4.6.6, in which a malicious packet trace could crash the application during TLS ECH decryption. Version 4.6.7 fixed the issue; Wireshark said it was unaware of exploitation in the wild.
Anthropic's Claude and Ada Logics researcher David Korczynski reported that repeated ECH outer-extension entries in a crafted PCAPNG could overflow Wireshark's TLS transcript buffer. The capture could embed a Decryption Secrets Block to supply the HPKE secret, allowing the malicious inner ClientHello to be decrypted and processed when opened.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
gitlab.com
Open sourcewireshark.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.