Junglewise Threat Intelligence

CVE-2026-5402: Wireshark TLS protocol dissector heap overflow

CVE-2026-5402 · Severity: high · CVSS 8.8 · Published 2026-04-30

Technologies: Wireshark. Vendors: Wireshark Foundation, Wireshark.

Executive brief

Wireshark, a widely used network protocol analyzer, is vulnerable to a flaw in how it processes encrypted web traffic (TLS). An attacker can exploit this by sending a malicious network packet or tricking a user into opening a specially crafted capture file. This could lead to the application crashing or, in some cases, allow the attacker to execute unauthorized code on the user's system.

Technical details

A heap-based buffer overflow exists in Wireshark's TLS Encrypted Client Hello (ECH) transcript reconstruction code. The vulnerability is caused by integer truncation and unsigned underflow issues during the processing of 'ech_outer_extensions'. Specifically, truncation in the extensions loop allows an attacker to write controlled data past the bounds of a heap-allocated buffer. An attacker can trigger this by injecting a malformed TLS ClientHello packet into live traffic being captured or by providing a crafted .pcapng file for analysis. This can result in a crash (DoS) or arbitrary code execution. The issue is resolved in Wireshark version 4.6.5.

Affected products

  • Wireshark Foundation Wireshark 4.6.0 to 4.6.4

Timeline

  • 2026-04-29: advisory: Wireshark published wnpa-sec-2026-14
  • 2026-04-30: disclosed: CVE-2026-5402 published to NVD
  • 2026-04-30: patched: Wireshark 4.6.5 released to address the issue

References

Related threats