CVE-2026-5402

HIGH

Heap-based Buffer Overflow in Wireshark

Title source: cna
STIX 2.1

Description

TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution

Scores

CVSS v3 8.8
EPSS 0.0004
EPSS Percentile 11.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-122
Status published
Products (1)
Wireshark Foundation/Wireshark 4.6.0 - 4.6.5
Published Apr 30, 2026
Tracked Since Apr 30, 2026