{"id":"CVE-2026-76886","summary":"Heap-based Buffer Overflow in Wireshark","details":"C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service","modified":"2026-08-30T03:48:17.469156327Z","published":"2026-08-19T22:35:24.922Z","related":["openSUSE-SU-2026:11579-1"],"database_specific":{"cwe_ids":["CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76886.json","unresolved_ranges":[{"extracted_events":[{"introduced":"4.6.0"},{"fixed":"4.6.8"},{"introduced":"4.4.0"},{"fixed":"4.4.18"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"GitLab"},"references":[{"type":"WEB","url":"https://gitlab.com/wireshark/wireshark/-/work_items/21439"},{"type":"WEB","url":"https://www.wireshark.org/security/wnpa-sec-2026-75.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76886.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76886"},{"type":"EVIDENCE","url":"https://gitlab.com/wireshark/wireshark/-/work_items/21446"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wireshark/wireshark","events":[{"introduced":"009a163470b581c7d3ee66d89c819cef1f9e50fe"},{"fixed":"b6c99a3f2a1aecf7926e7e64a94488b2bd071571"},{"introduced":"cdfb6721e77c19d43f4787f66e9d5f2525281a22"},{"fixed":"e677bf052328efc1ed897a547fa161836a0e4ff7"}],"database_specific":{"cpe":"cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.4.0"},{"fixed":"4.4.18"},{"introduced":"4.6.0"},{"fixed":"4.6.8"}],"source":"CPE_RANGE"}}],"versions":["v4.4.18rc0","v4.6.8rc0","v4.4.17","v4.6.7","v4.4.17rc0","v4.6.16","v4.4.16","v4.6.6","v4.6.6rc0","v4.4.16rc0","v4.4.15","v4.6.5","v4.4.15rc0","v4.6.5rc0","v4.4.14","v4.6.4","v4.4.14rc0","v4.6.4rc0","v4.4.13","v4.6.3","v4.4.13rc0","v4.4.12","v4.6.3rc0","v4.6.2","v4.4.12rc0","v4.6.2rc0","v4.4.11","v4.6.1","v4.4.11rc0","v4.6.1rc0","v4.4.10","v4.6.0","v4.4.10rc0","wireshark-4.4.9","v4.4.9","v4.4.9rc0","wireshark-4.4.8","v4.4.8","v4.4.8rc0","wireshark-4.4.7","v4.4.7","v4.6.7rc0","v4.4.7rc0","wireshark-4.4.6","v4.4.6","v4.4.6rc0","wireshark-4.4.5","v4.4.5","v4.4.5rc0","wireshark-4.4.4","v4.4.4","v4.4.4rc0","wireshark-4.4.3","v4.4.3","v4.4.3rc0","wireshark-4.4.2","v4.4.2","v4.4.2rc0","wireshark-4.4.1","v4.4.1","v4.4.1rc0","wireshark-4.4.0","v4.4.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-76886.json"}},{"ranges":[{"type":"GIT","repo":"https://gitlab.com/wireshark/wireshark","events":[{"introduced":"009a163470b581c7d3ee66d89c819cef1f9e50fe"},{"fixed":"b6c99a3f2a1aecf7926e7e64a94488b2bd071571"},{"introduced":"cdfb6721e77c19d43f4787f66e9d5f2525281a22"},{"fixed":"e677bf052328efc1ed897a547fa161836a0e4ff7"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.4.0"},{"fixed":"4.4.18"},{"introduced":"4.6.0"},{"fixed":"4.6.8"}]}}],"versions":["v4.4.18rc0","v4.6.8rc0","v4.4.17","v4.6.7","v4.4.17rc0","v4.6.7rc0","v4.4.16","v4.6.6","v4.6.6rc0","v4.4.16rc0","v4.4.15","v4.6.5","v4.4.15rc0","v4.6.5rc0","v4.4.14","v4.6.4","v4.4.14rc0","v4.6.4rc0","v4.4.13","v4.6.3","v4.4.13rc0","v4.4.12","v4.6.3rc0","v4.6.2","v4.4.12rc0","v4.6.2rc0","v4.4.11","v4.6.1","v4.4.11rc0","v4.6.1rc0","v4.4.10","v4.6.0","v4.4.10rc0","wireshark-4.4.9","v4.4.9","v4.4.9rc0","wireshark-4.4.8","v4.4.8","v4.4.8rc0","wireshark-4.4.7","v4.4.7","v4.4.7rc0","wireshark-4.4.6","v4.4.6","v4.4.6rc0","wireshark-4.4.5","v4.4.5","v4.4.5rc0","wireshark-4.4.4","v4.4.4","v4.4.4rc0","wireshark-4.4.3","v4.4.3","v4.4.3rc0","wireshark-4.4.2","v4.4.2","v4.4.2rc0","wireshark-4.4.1","v4.4.1","v4.4.1rc0","wireshark-4.4.0","v4.4.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-76886.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}