Back

HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark

Published Apr 30, 2026

Description

Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

Affected products

Remediation

Vendor solution

Upgrade to version 4.6.5 or above

Red Hat statement

This issue will cause a crash in Wireshark and potentially result in code execution. This flaw can only be exploited when a malformed configuration profile is imported. Due to these reasons, this vulnerability has been rated with an important severity.

Red Hat mitigation

To mitigate this flaw, do not import configuration profiles from untrusted or unverified sources.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitLab
Published Apr 30, 2026
Updated Jul 15, 2026
Reserved Apr 6, 2026

CISA Vulnrichment

Updated May 1, 2026

NVD

Status Modified
Modified Jul 15, 2026

Red Hat

Severity Important
Public date Apr 30, 2026
Bugzilla 2464276

ENISA EUVD

Assigner GitLab
Published Apr 30, 2026
Updated Jul 15, 2026

GitHub

No data