CVE-2026-19694
PoC massHeap buffer overflow in Wireshark TTX Logger parser causes crash DoS
Wireshark versions 4.6.0 through 4.6.7 contain a heap-based buffer overflow (CWE-122) in the TTX Logger file parser, the component used to read TTX Logger capture files. The flaw is triggered when the parser processes a crafted or malformed TTX Logger file, and the CVSS vector (local attack vector, user interaction required) means an attacker needs a local user to open the malicious file. Successful exploitation crashes the application, producing a denial of service with no confidentiality or integrity impact. Anyone running Wireshark 4.6.0 through 4.6.7 is affected, especially users who open capture files obtained from untrusted sources. No in-the-wild exploitation is known: the issue is documented with a public PoC reference on the Wireshark GitLab tracker, EPSS is 0.1% (3rd percentile), and it is not in CISA KEV.
What to do: Check the installed Wireshark version and upgrade to a release newer than 4.6.7 when available from wireshark.org. As an interim mitigation, do not open TTX Logger capture files from untrusted or unexpected sources with affected 4.6.x builds; the flaw only causes a crash, so risk is limited to availability.
| Wireshark | 4.6.0 through 4.6.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service
- Vendors
- wireshark
- Products
- wireshark
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.