
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19696 is a denial-of-service vulnerability in the Ixia IxVeriWave and Vector Informatik BLF (Binary Logging Format) file parser within Wireshark, affecting versions 4.6.0 through 4.6.7 on Windows. The vulnerability was published on August 13, 2026, and is classified as Moderate severity with a CVSS v3.1 base score of 6.6 (GitHub Advisory, Wireshark Advisory). The fix is available in Wireshark 4.6.8 and later (GitHub Advisory).
The vulnerability is rooted in an out-of-bounds write (CWE-787) in the BLF file parser used to process Ixia IxVeriWave and Vector Informatik capture files. When Wireshark processes a specially crafted malformed BLF file, the parser writes data beyond the bounds of an allocated buffer, causing an application crash. Exploitation requires local access and user interaction — specifically, a user must open a malicious BLF file — and no elevated privileges are needed (GitHub Advisory, Wireshark GitLab).
Successful exploitation causes the Wireshark application to crash, resulting in a denial of service for the affected user on Windows systems. The vulnerability also carries low confidentiality and integrity impacts, suggesting the out-of-bounds write may expose limited memory contents or corrupt data in addition to crashing the application. The scope is limited to the local user's session and does not enable remote code execution or lateral movement based on currently available information (GitHub Advisory).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an attacker to convince a local user to open a malicious BLF file, limiting the practical attack surface.
.blf files in user download directories or shared folders.Wireshark.exe) crash events (Event ID 1000) with faulting module related to BLF parsing.%LOCALAPPDATA%\CrashDumps\.Users should upgrade Wireshark to version 4.6.8 or later, which contains the fix for this vulnerability (Wireshark Advisory). As interim workarounds, restrict local file access and user permissions to trusted users only, and avoid opening BLF files from untrusted sources. Implementing input validation or file type filtering before processing BLF files can further reduce exposure (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."