CVE-2026-0960
Wireshark vulnerability analysis and mitigation

Overview

CVE-2026-0960 is an infinite loop vulnerability in the HTTP3 protocol dissector of Wireshark that allows a local attacker to cause a denial of service. It affects Wireshark versions 4.6.0 through 4.6.2 (fixed in 4.6.3) and versions 4.4.0 through 4.4.12 (fixed in 4.4.13). The vulnerability was first reported on January 14, 2026, and received initial NVD analysis on January 21, 2026. It carries a CVSS v3.1 base score of 5.5 (Medium) per NVD, or 4.7 (Medium) per the CNA (GitLab Inc.) (Wireshark Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-835 (Loop with Unreachable Exit Condition / Infinite Loop), where the HTTP3 protocol dissector in Wireshark enters an infinite processing loop when parsing specially crafted capture files containing malformed HTTP3 traffic. Exploitation requires user interaction — specifically, a victim must open a maliciously crafted packet capture file (e.g., .pcap or .pcapng) containing the malformed HTTP3 data. The attack vector is local (AV:L), meaning the attacker must deliver the malicious file to the victim's system, but no special privileges are required. The Wireshark GitLab issue tracker serves as the primary technical reference (Wireshark GitLab, Wireshark Advisory).

Impact

Successful exploitation causes Wireshark to enter an infinite loop, rendering the application unresponsive and effectively crashing it, resulting in a denial of service. There is no impact on confidentiality or integrity — only availability is affected. This could disrupt security operations teams or network analysts who rely on Wireshark for packet analysis, potentially delaying incident response or forensic investigations (Red Hat Bugzilla, Wireshark Advisory).

Exploitation steps

  1. Craft malicious capture file: Create a specially crafted .pcap or .pcapng file containing malformed HTTP3 protocol traffic designed to trigger the infinite loop condition in Wireshark's HTTP3 dissector.
  2. Deliver the file: Use social engineering, email attachment, shared network drive, or other means to deliver the malicious capture file to a target system where Wireshark 4.6.0–4.6.2 or 4.4.0–4.4.12 is installed.
  3. Trigger the vulnerability: Convince the victim to open the malicious capture file in Wireshark (e.g., by disguising it as a legitimate network capture or analysis artifact).
  4. Achieve denial of service: Upon opening the file, Wireshark's HTTP3 dissector enters an infinite loop, causing the application to hang and become unresponsive, disrupting any ongoing packet analysis operations (Wireshark GitLab, Wireshark Advisory).

Indicators of compromise

  • File System: Presence of unexpected or unsolicited .pcap, .pcapng, or other packet capture files in user directories, downloads folders, or shared drives containing HTTP3 traffic patterns.
  • Process: Wireshark process (wireshark.exe or wireshark) consuming 100% CPU for an extended period without user interaction or progress, indicating an infinite loop condition.
  • Logs: Application crash reports or hang reports associated with the Wireshark process; OS-level event logs showing Wireshark becoming unresponsive or being forcibly terminated.

Mitigation and workarounds

Wireshark has released patched versions 4.6.3 and 4.4.13 that resolve this vulnerability. Users running Wireshark 4.6.0–4.6.2 or 4.4.0–4.4.12 should upgrade immediately. As a workaround prior to patching, avoid opening untrusted or unsolicited packet capture files, implement file validation procedures before opening captures in Wireshark, and restrict Wireshark usage to trusted file sources and networks (Wireshark Advisory, Red Hat Bugzilla).

Community reactions

Red Hat tracked the vulnerability via their security response process (Bugzilla Bug 2429762) and assessed it as medium severity. Debian issued security updates (DSA-6124-1 and DLA-4479-1) addressing this and related Wireshark vulnerabilities. SUSE and Fedora also released package updates. Coverage has been largely routine, with no significant controversy or notable researcher commentary beyond standard patch announcements (Red Hat Bugzilla, Wireshark Advisory).

Additional resources


SourceThis report was generated using AI

Related Wireshark vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15174MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark-cli
NoYesJul 08, 2026
CVE-2026-15173MEDIUM5.5
  • Wireshark logoWireshark
  • cpe:2.3:a:wireshark:wireshark
NoYesJul 08, 2026
CVE-2026-15172MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark-cli-debuginfo
NoYesJul 08, 2026
CVE-2026-15171MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark
NoYesJul 08, 2026
CVE-2026-15168LOW3.3
  • Wireshark logoWireshark
  • wireshark-cli
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management