Skip to main content
CVE Vulnerability Database

CVE-2026-6868: Wireshark HTTP Dissector DoS Vulnerability

CVE-2026-6868 is a denial of service flaw in Wireshark's HTTP protocol dissector affecting versions 4.6.0-4.6.4 and 4.4.0-4.4.14. This vulnerability allows attackers to crash the application and disrupt network analysis.

Published:

CVE-2026-6868 Overview

CVE-2026-6868 is a denial of service vulnerability in the HTTP protocol dissector of Wireshark, a widely-used network protocol analyzer. The vulnerability affects Wireshark versions 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14. When processing specially crafted network capture files or live traffic containing malformed HTTP data, the application may crash due to a stack-based buffer overflow (CWE-121), causing service disruption for security analysts and network administrators relying on the tool.

Critical Impact

Attackers can craft malicious packet captures that crash Wireshark when opened or when live traffic is captured, disrupting network analysis and incident response workflows.

Affected Products

  • Wireshark 4.6.0 to 4.6.4
  • Wireshark 4.4.0 to 4.4.14

Discovery Timeline

  • 2026-04-30 - CVE-2026-6868 published to NVD
  • 2026-04-30 - Last updated in NVD database

Technical Details for CVE-2026-6868

Vulnerability Analysis

This vulnerability resides in Wireshark's HTTP protocol dissector, a component responsible for parsing and displaying HTTP traffic during packet capture analysis. The flaw is classified as CWE-121 (Stack-based Buffer Overflow), indicating that the dissector fails to properly validate input boundaries when processing HTTP data, allowing malformed packets to write beyond allocated stack buffer limits.

The local attack vector means an attacker must convince a user to open a malicious capture file (.pcap, .pcapng) or capture traffic from a network under attacker control. While no remote exploitation is possible without user interaction, this remains a significant risk in environments where analysts routinely open capture files from untrusted sources or monitor networks containing attacker-controlled traffic.

The vulnerability results in availability impact only, causing the Wireshark application to crash without compromising confidentiality or integrity of the system.

Root Cause

The root cause is a stack-based buffer overflow (CWE-121) in the HTTP protocol dissector. Insufficient bounds checking when parsing HTTP headers or body content allows specially crafted input to overflow stack-allocated buffers, corrupting adjacent memory and causing the application to crash.

Attack Vector

The attack requires local access, meaning an attacker must either:

  1. Provide a victim with a malicious packet capture file containing crafted HTTP traffic that triggers the buffer overflow when opened in Wireshark
  2. Have the victim capture live traffic from a network where the attacker can inject malformed HTTP packets

When the vulnerable HTTP dissector processes the malicious data, it fails to properly validate input length, resulting in a stack buffer overflow that crashes the application. The vulnerability can be triggered by specially crafted HTTP protocol data within network captures.

For detailed technical information about the exploitation mechanism, refer to the GitLab Wireshark Work Item and the Wireshark Security Advisory WNPA-SEC-2026-46.

Detection Methods for CVE-2026-6868

Indicators of Compromise

  • Unexpected Wireshark process terminations during HTTP traffic analysis
  • Crash dumps or core files from Wireshark with stack traces pointing to HTTP dissector functions
  • Reports of application crashes when opening specific .pcap or .pcapng files
  • Wireshark crash logs indicating buffer overflow or memory corruption in HTTP dissector modules

Detection Strategies

  • Monitor for abnormal Wireshark process terminations and restart patterns
  • Implement file scanning for capture files before opening in Wireshark
  • Use SentinelOne endpoint protection to detect and alert on application crashes indicative of exploitation attempts
  • Deploy application crash monitoring to identify repeated dissector failures

Monitoring Recommendations

  • Enable detailed logging for Wireshark crash events in enterprise environments
  • Monitor endpoint telemetry for patterns of Wireshark crashes correlated with specific file access
  • Implement SentinelOne behavioral AI to detect anomalous application termination patterns
  • Track file provenance for packet captures opened by analysts

How to Mitigate CVE-2026-6868

Immediate Actions Required

  • Upgrade Wireshark to a patched version beyond 4.6.4 or 4.4.14 respectively
  • Avoid opening packet capture files from untrusted or unknown sources
  • Consider using TShark in batch mode with limited protocol dissection for untrusted captures
  • Disable the HTTP dissector temporarily if immediate patching is not possible

Patch Information

Wireshark has addressed this vulnerability in versions released after 4.6.4 and 4.4.14. Refer to the Wireshark Security Advisory WNPA-SEC-2026-46 for specific patched version information and download links. Organizations should update to the latest stable release from the official Wireshark download page.

Workarounds

  • Disable HTTP protocol dissection using Wireshark's protocol disable feature via Analyze > Enabled Protocols
  • Use TShark with -d options to exclude HTTP dissection when analyzing untrusted captures
  • Implement file sandboxing when opening capture files from external sources
  • Run Wireshark in an isolated virtual machine when analyzing suspicious network data
bash
# Disable HTTP dissector via command line
tshark -o "http.desegment_body:FALSE" -r untrusted_capture.pcap

# Alternative: Use display filter to exclude HTTP and prevent dissection
wireshark -Y "not http" -r capture_file.pcap

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.