CVE-2026-3201 is a denial-of-service vulnerability affecting Wireshark versions 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13, specifically within the USB HID protocol dissector. This flaw can lead to memory exhaustion. With a CVSS score of 7.5 (High), it can be exploited remotely without authentication, resulting in a complete loss of availability. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating awareness and concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.4.0, < 4.4.14CPE match | cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* | ||
>= 4.6.0, < 4.6.4CPE match | cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.