CVE-2026-19696
Wireshark vulnerability analysis and mitigation

Overview

CVE-2026-19696 is a denial-of-service vulnerability in the Ixia IxVeriWave and Vector Informatik BLF (Binary Logging Format) file parser within Wireshark, affecting versions 4.6.0 through 4.6.7 on Windows. The vulnerability was published on August 13, 2026, and is classified as Moderate severity with a CVSS v3.1 base score of 6.6 (GitHub Advisory, Wireshark Advisory). The fix is available in Wireshark 4.6.8 and later (GitHub Advisory).

Technical details

The vulnerability is rooted in an out-of-bounds write (CWE-787) in the BLF file parser used to process Ixia IxVeriWave and Vector Informatik capture files. When Wireshark processes a specially crafted malformed BLF file, the parser writes data beyond the bounds of an allocated buffer, causing an application crash. Exploitation requires local access and user interaction — specifically, a user must open a malicious BLF file — and no elevated privileges are needed (GitHub Advisory, Wireshark GitLab).

Impact

Successful exploitation causes the Wireshark application to crash, resulting in a denial of service for the affected user on Windows systems. The vulnerability also carries low confidentiality and integrity impacts, suggesting the out-of-bounds write may expose limited memory contents or corrupt data in addition to crashing the application. The scope is limited to the local user's session and does not enable remote code execution or lateral movement based on currently available information (GitHub Advisory).

Exploitability

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an attacker to convince a local user to open a malicious BLF file, limiting the practical attack surface.

Exploitation steps

  1. Craft malicious BLF file: Create a specially malformed Binary Logging Format (BLF) file designed to trigger an out-of-bounds write in Wireshark's Ixia IxVeriWave or Vector Informatik BLF parser.
  2. Deliver the file: Deliver the malicious BLF file to a target running Wireshark 4.6.0–4.6.7 on Windows via email attachment, file share, or social engineering.
  3. Trigger parsing: Convince the target user to open the malicious BLF file in Wireshark (e.g., via File > Open or drag-and-drop), initiating the vulnerable parser.
  4. Achieve denial of service: The out-of-bounds write causes Wireshark to crash, denying the user access to the application and any ongoing capture or analysis session (GitHub Advisory, Wireshark GitLab).

Indicators of compromise

  • File System: Presence of unexpected or externally sourced .blf files in user download directories or shared folders.
  • Logs: Windows Event Logs (Application) showing Wireshark (Wireshark.exe) crash events (Event ID 1000) with faulting module related to BLF parsing.
  • Process: Wireshark process terminating unexpectedly shortly after opening a BLF file, potentially generating a Windows Error Reporting (WER) crash dump in %LOCALAPPDATA%\CrashDumps\.

Mitigation and workarounds

Users should upgrade Wireshark to version 4.6.8 or later, which contains the fix for this vulnerability (Wireshark Advisory). As interim workarounds, restrict local file access and user permissions to trusted users only, and avoid opening BLF files from untrusted sources. Implementing input validation or file type filtering before processing BLF files can further reduce exposure (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Wireshark vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19696MEDIUM6.6
  • Wireshark logoWireshark
  • cpe:2.3:a:wireshark:wireshark
NoYesAug 13, 2026
CVE-2026-15174MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark-ui-qt
NoYesJul 08, 2026
CVE-2026-19695MEDIUM4.7
  • Wireshark logoWireshark
  • cpe:2.3:a:wireshark:wireshark
NoYesAug 13, 2026
CVE-2026-19694MEDIUM4.7
  • Wireshark logoWireshark
  • cpe:2.3:a:wireshark:wireshark
NoYesAug 13, 2026
CVE-2026-15168LOW3.3
  • Wireshark logoWireshark
  • wireshark-gnome
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management