
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5406 is an uncontrolled recursion vulnerability in Wireshark's FC-SWILS (Fibre Channel Switch Fabric Internal Link Services) protocol dissector that allows denial of service via application crash. It affects Wireshark versions 4.4.0 through 4.4.14 and 4.6.0 through 4.6.4. The vulnerability was published on April 30, 2026, with patches released in the same timeframe. It carries a CVSS v3.1 base score of 5.5 (Medium), assigned by GitLab (GitHub Advisory, Wireshark Advisory).
The root cause is classified as CWE-674 (Uncontrolled Recursion): the FC-SWILS dissector does not properly limit recursion depth when processing nested zone set objects, leading to a stack overflow and application crash. An attacker can trigger this by crafting a malicious PCAP file or network packet containing deeply nested FC-SWILS zone set structures, which causes Wireshark to recurse without bound when parsing the data. Exploitation requires local access and user interaction — specifically, a victim must open a malicious capture file or analyze crafted live traffic. The GitLab issue tracker entry (titled "FC-SWILS dissector stack overflow via nested zone set objects") documents the flaw (GitLab Issue, GitHub Advisory).
Successful exploitation causes Wireshark to crash, resulting in a denial of service for network analysts and security professionals relying on the tool for traffic analysis. There is no impact on confidentiality or data integrity — the vulnerability is limited to availability of the Wireshark application itself. Because exploitation requires local access and user interaction, the blast radius is confined to individual analyst workstations rather than enabling lateral movement or remote system compromise (GitHub Advisory, Wireshark Advisory).
A GitLab issue report exists documenting the stack overflow behavior, but it does not contain functional exploit code — it is classified as an advisory rather than a working exploit (GitLab Issue). There is no evidence of in-the-wild exploitation, no threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term (GitHub Advisory).
Users should upgrade to Wireshark 4.6.5 or later (for the 4.6.x branch) or 4.4.15 or later (for the 4.4.x branch), which contain fixes for this vulnerability (Wireshark Advisory, Release Notes). As a temporary workaround prior to patching, avoid opening PCAP files from untrusted sources and refrain from analyzing network traffic from untrusted environments. Restricting Wireshark usage to trusted, controlled environments and limiting which users can open arbitrary capture files also reduces exposure.
Wireshark announced the fix via its official mailing lists (wireshark-announce and wireshark-users) in April and May 2026, and the security advisory was published at wnpa-sec-2026-10 (Wireshark Announce, Wireshark Advisory). Security news outlets including CyberSecurityNews and Cryptika covered the broader set of Wireshark vulnerabilities disclosed in this release cycle. Downstream Linux distributions including Debian and SUSE issued their own advisories and package updates incorporating the fix (Linux Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."