LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-6536 - Vulnerability Analysis

MediumCVSS: 5.5

Last Updated: May 1, 2026

Wireshark - Denial of Service

Published: April 30, 2026Updated: May 1, 2026PoC Available

Overview

Wireshark 4.6.0 to 4.6.4 contains an infinite loop vulnerability in the DLMS/COSEM protocol dissector, letting remote attackers cause denial of service by triggering the loop, exploit requires crafted network packets.

Severity & Score

Severity: Medium
CVSS Score: 5.5

Impact

Remote attackers can cause denial of service by triggering an infinite loop, potentially crashing or hanging the application.

Mitigation

Update to the latest version beyond 4.6.4.

Details

CVE ID
CVE-2026-6536
Severity
Medium
CVSS Score
5.5
Type
denial_of_service
Status
confirmed

CWE

  • CWE-835

CVSS Metrics

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H