
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5299 is a denial-of-service vulnerability caused by uncontrolled recursion in Wireshark's ICMPv6 PvD (Prefix Validation Data) protocol dissector. It affects Wireshark versions 4.6.0 through 4.6.4 and 4.4.0 through 4.4.14. The vulnerability was published on April 30, 2026, and assigned by GitLab. It carries a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory, Wireshark Advisory).
The root cause is CWE-674 (Uncontrolled Recursion): the ICMPv6 PvD dissector fails to properly limit the depth of recursive processing when parsing malformed ICMPv6 packets, leading to excessive resource consumption and an application crash. Exploitation requires a local attack vector with user interaction — specifically, a user must open or analyze a crafted packet capture file containing malicious ICMPv6 PvD packets. The vulnerability is tracked in the Wireshark issue tracker as issue #21077 (Wireshark Issue, GitHub Advisory).
Successful exploitation results in a crash of the Wireshark application, causing a denial-of-service condition that renders packet analysis capabilities unavailable. There is no impact on confidentiality or data integrity — only availability is affected. Users may also lose unsaved analysis work at the time of the crash (GitHub Advisory, Wireshark Advisory).
A proof-of-concept reference exists in the form of the Wireshark GitLab issue (#21077), though it does not contain weaponized exploit code (Wireshark Issue). There is no evidence of active in-the-wild exploitation, no threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.013% (2nd percentile), indicating a very low probability of exploitation in the near term (GitHub Advisory).
.pcap or .pcapng files received from external sources, particularly those containing ICMPv6 traffic.Users should upgrade to Wireshark version 4.6.5 or later (for the 4.6.x branch) or version 4.4.15 or later (for the 4.4.x branch) to remediate this vulnerability (Wireshark Advisory, Release Notes). As a temporary workaround prior to patching, avoid opening untrusted or externally sourced pcap files in affected Wireshark versions, and restrict Wireshark usage to trusted capture sources only. Nessus detection plugins (IDs 311593, 313009, 313625) are available to identify vulnerable installations (Tenable).
The Wireshark project published a security advisory (wnpa-sec-2026-12) and release announcements via their mailing lists upon disclosure (Wireshark Announce). Security news outlets including CyberSecurityNews and Cryptika covered the broader set of Wireshark vulnerabilities disclosed alongside CVE-2026-5299, with some headlines emphasizing code execution risks from the broader release (CyberSecurityNews). Linux distribution security teams, including Debian, issued advisories and package updates addressing this and related Wireshark vulnerabilities (LinuxSecurity).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."