CVE-2026-6535
Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.5
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS probability
- 0.14%
- CWE
- CWE-1325
- Published
- 2026-04-30
- Last modified
- 2026-04-30
Affected products
- Wireshark Foundation Wireshark
- Wireshark Foundation Wireshark
Weakness type
Related vulnerabilities
- CVE-2026-71436 — Mermaid XY Charts are vulnerable to an infinite loop DoS
- CVE-2026-18772 — Improper input validation vulnerability in Samsung Open Source rlottie allows Oversized Serialized...
- CVE-2026-54081 — veraPDF Parser DoS via PostScript Type 1 Font Programs
- CVE-2026-54080 — veraPDF Parser DoS via PostScript CMap Streams
- CVE-2026-13056 — A user with read access can cause a DoS by executing a specifically crafted query to consume a large amount of RAM
- CVE-2026-34183 — Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler
- CVE-2026-8199 — Post-auth memory exhaustion via bitwise match expressions
- CVE-2026-6533 — Improperly Controlled Sequential Memory Allocation in Wireshark