Description
TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
Published: 2026-07-08
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a heap‑based buffer overflow located in the TLS ECH decryptor component of Wireshark versions 4.6.0 through 4.6.6. When a crafted TLS ECH packet is processed, the heap overflow can corrupt memory and trigger a crash, thereby causing Wireshark to stop processing packets and potentially deny service to users who rely on the software for network analysis. The weaknesses are classified as CWE‑122 and CWE‑617.

Affected Systems

Wireshark Foundation’s Wireshark 4.6.0 to 4.6.6 are affected. All installations of these versions that use the TLS ECH decryptor feature are vulnerable. Updating to version 4.6.7 or later removes the vulnerability.

Risk and Exploitability

The CVSS base score of 5.5 indicates medium severity. The EPSS score of <1% shows a very low probability of exploitation, and it is not present in the CISA KEV catalog. The likely attack vector is the processing of a malicious TLS ECH packet received over the network, potentially delivered remotely via a client or a compromised certificate authority. Attackers would need only to send such a packet to a system running the vulnerable Wireshark instance; the crash leads to denial of service to users of that instance.

Generated by OpenCVE AI on July 29, 2026 at 13:20 UTC.

Remediation

Vendor Solution

Upgrade to version 4.6.7 or above


OpenCVE Recommended Actions

  • Upgrade Wireshark to version 4.6.7 or later
  • Monitor network traffic for unusual TLS ECH packets and consider blocking suspicious packets at the firewall or IDS to reduce exposure
  • Check the vendor's website for updates or patches on a regular basis

Generated by OpenCVE AI on July 29, 2026 at 13:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-617
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 08 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Wireshark
Wireshark wireshark
Vendors & Products Wireshark
Wireshark wireshark

Wed, 08 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
Title Heap-based Buffer Overflow in Wireshark
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Wireshark Wireshark
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-07-09T13:47:02.064Z

Reserved: 2026-07-08T20:45:23.874Z

Link: CVE-2026-15165

cve-icon Vulnrichment

Updated: 2026-07-09T13:46:49.220Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-08T20:50:45Z

Links: CVE-2026-15165 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T13:30:06Z

Weaknesses