CVE-2026-15170: Wireshark Z39.50 Dissector DoS Vulnerability (Medium)
Wireshark, the widely-used network analysis tool, contains a flaw in how it processes Z39.50 protocol traffic that can cause the application to crash. An attacker or malicious network traffic could trigger this crash, disrupting network troubleshooting and monitoring operations. This affects Wireshark versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16. The vulnerability requires local access and user interaction to exploit, limiting its attack surface.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 5.5 MEDIUM · CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- Weaknesses (CWE)
- CWE-122
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-07-08 / 2026-07-09
NVD description (verbatim)
Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
3 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
A buffer over-read vulnerability (CWE-122) exists in Wireshark's Z39.50 protocol dissector. The dissector fails to properly validate or bound-check packet data during parsing, leading to out-of-bounds memory access. When a specially crafted Z39.50 packet is processed—either through live packet capture or pcap file analysis—the memory violation causes an unhandled exception and application crash. The vulnerability is triggered only when the user actively initiates packet capture or opens a malicious pcap file, and requires the Z39.50 dissector to be active during traffic inspection.
Business impact
Wireshark downtime disrupts incident response workflows, network troubleshooting, and continuous monitoring capabilities. During active security investigations or network diagnostics, unexpected crashes can delay root-cause analysis and extend mean-time-to-resolution. Organizations relying on Wireshark for compliance logging or packet retention may experience gaps in audit trails if the application terminates unexpectedly. The impact is primarily operational rather than exposing sensitive data.
Affected systems
Affected versions are Wireshark 4.6.0–4.6.6 (current stable branch) and 4.4.0–4.4.16 (extended support branch). Organizations running other major versions (e.g., 4.2.x, 4.0.x, or 5.x) should verify their version numbers, as this advisory covers only the stated ranges. The vulnerability affects Wireshark on all operating systems (Windows, macOS, Linux) where these versions are deployed.
Exploitability
Exploitability is limited by attack prerequisites. An attacker must either (1) control network traffic that passes through a Wireshark capture session, or (2) deliver a malicious pcap file to a user who then opens it in Wireshark. Both scenarios require user action or network position. The local-access vector and requirement for user interaction (opening a file or actively capturing at the moment malicious traffic arrives) significantly reduces real-world exploitation likelihood compared to remote, unauthenticated vulnerabilities. No known public exploits or active weaponization have been reported.
Remediation
Update Wireshark to patched versions as released by the Wireshark Foundation. Verify the specific patched version numbers against the official Wireshark security advisory and release notes. As an interim measure, users can disable or uninstall the Z39.50 dissector plugin if Z39.50 analysis is not required, or restrict packet capture to trusted network segments. Do not share untrusted pcap files with colleagues using vulnerable versions.
Patch guidance
Consult the Wireshark Foundation's official security advisory for exact patched version numbers and download links. Patches are typically released for both the 4.6.x and 4.4.x branches. Test patches in a non-production environment before enterprise rollout, particularly if Wireshark integrations or automated packet processing scripts depend on specific version behavior. Automated update mechanisms (if available) can accelerate deployment.
Detection guidance
Monitor Wireshark process logs and system event logs for unexpected application crashes, particularly correlated with Z39.50 traffic analysis or pcap file loading. Deploy endpoint detection tools that alert on repeated application crashes on analyst workstations. If Z39.50 analysis is not used operationally, network segmentation or firewall rules can prevent Z39.50 traffic (typically port 210) from reaching analytical segments. Pcap file integrity checks and sandboxed analysis of untrusted captures can reduce exposure.
Why prioritize this
While the CVSS score of 5.5 (medium) reflects limited attack surface, the vulnerability affects a security-critical tool widely deployed in SOCs and incident response teams. Any disruption to Wireshark operations during active incidents has downstream consequences. Organizations should prioritize patching Wireshark in their standard update cycles but may deprioritize over vulnerabilities affecting internet-facing or authentication systems. The lack of active exploitation and KEV designation supports a measured, planned approach rather than emergency patching.
Risk score, explained
The CVSS 3.1 score of 5.5 reflects a high availability impact (A:H) but limited attack vector (L for local) and user interaction requirement (UI:R). No confidentiality or integrity impact is possible. The score correctly captures that while the vulnerability reliably crashes the application, the attacker must already have local access or network position, and the victim must be actively using Wireshark at the time of exploitation. This score is appropriate for an operational denial-of-service against a non-critical tool, though the actual business risk depends on organizational reliance on Wireshark.
Frequently asked questions
If I'm running Wireshark 4.2.x or 5.x, am I affected?
No. This advisory covers only versions 4.6.0–4.6.6 and 4.4.0–4.4.16. If you are unsure of your version, select Help > About Wireshark to confirm. Other major versions may have their own vulnerabilities; always check release notes when updating.
Can this vulnerability be exploited remotely without user action?
No. The attacker must either send Z39.50 traffic during an active capture session they can observe, or trick a user into opening a malicious pcap file. Neither scenario is a remote, unauthenticated attack. The vulnerability is local-access and user-interaction dependent.
We don't analyze Z39.50 traffic. Should we still patch?
Yes. Disabling the Z39.50 dissector or removing the plugin is a reasonable interim control if Z39.50 analysis is truly unnecessary for your organization. However, patching is the recommended long-term remediation, as dissector plugins may be re-enabled during updates or by accident. Patching is also simpler than maintaining custom dissector configurations across your fleet.
Does this vulnerability leak sensitive packet data?
No. The vulnerability causes only a denial of service (application crash). There is no confidentiality or integrity impact. Wireshark will not expose or corrupt captured data; it will simply stop running. Unsaved packets will be lost if the application crashes without writing to disk.
This analysis is based on publicly available information as of the publication date. Patch version numbers and remediation details must be verified against the official Wireshark Foundation security advisory before deployment. No exploit code or detailed reproduction steps are provided. Organizations should conduct their own risk assessment based on their Wireshark deployment footprint and operational criticality. SEC.co makes no guarantees regarding the completeness or timeliness of this information. Source: NVD (public-domain), retrieved 2026-08-17. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-15164MEDIUMWireshark ciscodump Denial of Service Vulnerability
- CVE-2026-15165MEDIUMWireshark TLS ECH Denial of Service Vulnerability (4.6.0–4.6.6)
- CVE-2026-15169MEDIUMWireshark UMTS FP Protocol Dissector Denial of Service
- CVE-2026-15173MEDIUMWireshark pcapng Parser Denial of Service (MEDIUM)
- CVE-2026-15174MEDIUMWireshark Catapult DCT2000 Dissector DoS Vulnerability
- CVE-2025-15666MEDIUMAssimp Heap Buffer Overflow in Model File Handler
- CVE-2025-55645MEDIUMHeap Buffer Overflow in GPAC MP4Box v2.4 – DoS Vulnerability
- CVE-2025-55648MEDIUMGPAC MP4Box Heap Buffer Overflow DoS Vulnerability