ZeroHour

CVE-2026-76883

PoC mass

Heap-based buffer overflow in Wireshark Catapult DCT2000 parser causes DoS

CVSS 3.1
5.5 medium
EPSS
<1%p1
Published
()
Modified
AI analysis

CVE-2026-76883 is a heap-based buffer overflow (CWE-122) in the Catapult DCT2000 file parser of Wireshark, affecting releases 4.6.0 through 4.6.7 and 4.4.0 through 4.4.18. It is triggered when a user opens a crafted or corrupt Catapult DCT2000 capture file, with the CVSS vector (AV:L, UI:R) indicating a local, user-interaction-required attack rather than a network-triggered flaw. A successful exploit crashes the application, causing denial of service only; there is no confidentiality or integrity impact and the flaw is rated medium (CVSS 5.5). Anyone running Wireshark in the affected version ranges who handles capture files from this protocol is exposed, though Catapult DCT2000 is a specialized telecom diagnostic format, so practical exposure is limited to analysts who open such files. Exploitation is not known to be occurring in the wild: EPSS is 0.1%, the flaw is not in CISA KEV, and the only public reference is the Wireshark GitLab issue tracker item (work item 21427).

What to do: Update Wireshark to a release newer than the affected ranges — 4.6.8 or later on the 4.6 branch, or 4.4.19 or later on the 4.4 branch. Until patched, avoid opening untrusted Catapult DCT2000 capture files; check the installed version via Help > About Wireshark or tshark --version. This is a medium-severity local DoS with no known in-the-wild exploitation, so routine patching cadence is sufficient.

Affected
Wireshark4.6.0 through 4.6.7
Wireshark4.4.0 through 4.4.18
Estimated exposure
mass≈1M+ Wireshark installations worldwide, though only a fraction open Catapult DCT2000 files — Wireshark is the de facto standard open-source packet analyzer with millions of cumulative downloads across analyst and engineering workstations, so installs in the affected 4.4.x/4.6.x branches number in the millions even though this…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Vendors
wireshark
Products
wireshark
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.