HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service
History

Fri, 05 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:*

Fri, 05 Dec 2025 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 04 Dec 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Wireshark
Wireshark wireshark
Vendors & Products Wireshark
Wireshark wireshark

Wed, 03 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Dec 2025 08:15:00 +0000

Type Values Removed Values Added
Description HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service
Title Improperly Controlled Sequential Memory Allocation in Wireshark
Weaknesses CWE-1325
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published: 2025-12-03T08:04:49.403Z

Updated: 2025-12-03T15:59:28.435Z

Reserved: 2025-12-03T07:33:37.960Z

Link: CVE-2025-13945

cve-icon Vulnrichment

Updated: 2025-12-03T15:59:25.935Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-03T08:15:47.940

Modified: 2025-12-05T15:08:07.970

Link: CVE-2025-13945

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-12-03T08:04:49Z

Links: CVE-2025-13945 - Bugzilla