Sceawere

Vulnerability Detail

CVE-2026-95387UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SPDY Dissector Denial of Service

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
15h ago
Vendor
Wireshark Foundation
Product
Wireshark
Attack Type
CWE-122: Heap-based Buffer Overflow
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-09-29T10:17:14.713Z",
  "pubdate": "2026-09-29T10:17:14.713Z",
  "executiveSummary": "A vulnerability exists in the SPDY protocol dissector within the affected software versions, leading to a Denial of Service (DoS) condition.\nThe vulnerability is characterized by an improper handling of malformed or crafted SPDY protocol traffic, which triggers a crash in the protocol dissection component.\nAffected product versions include 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18.\nThe primary risk implication is the unavailability of the affected service or monitoring capabilities due to application process termination.\nAttackers can exploit this vulnerability remotely by sending specially crafted SPDY packets to the target system.\nNo authentication or elevated privileges are required for an attacker to initiate the crash, as the dissector processes incoming traffic prior to session establishment or authentication logic.\nSuccessful exploitation forces an immediate crash of the affected process, disrupting network traffic analysis or the underlying service relying on the dissector.",
  "technicalDetails": "The vulnerability resides in the protocol dissector logic responsible for parsing and interpreting SPDY frames. The root cause is an input validation flaw when processing specific field headers or malformed SPDY frame structures that lead to a buffer over-read, pointer dereference error, or integer overflow during the reassembly or parsing phase.\nIn the context of the affected protocol dissector, the application attempts to decode stream parameters or control frames. When an attacker provides a frame containing anomalous metadata—such as an invalid length field or mismatched stream associations—the parser fails to maintain memory safety or state consistency.\nThe attack flow begins when an attacker transmits a malicious SPDY frame over a network connection established with the target system. Because the dissector is positioned to inspect packets as they arrive, the payload does not require the attacker to have an active, authenticated session. Upon receipt, the dissector logic attempts to parse the header fields; the lack of rigorous bounds checking or state validation triggers an exception, usually resulting in a segmentation fault or a process-wide crash.\nBecause the crash occurs at the dissector layer, the impact is primarily service availability. If the affected product is used in a security monitoring context, the crash effectively blinds the security infrastructure to subsequent traffic. In scenarios where the product acts as a proxy or service handler, the vulnerability forces a reboot or service restart, allowing for persistent DoS if the attacker maintains the delivery of malicious packets.\nThe vulnerability affects versions 4.6.0-4.6.8 and 4.4.0-4.4.18. Exploitation requires only the ability to reach the service over the network port assigned to SPDY traffic. There are no specific post-exploitation artifacts mentioned, as the primary objective of this vulnerability is the termination of the host process rather than remote code execution."
}
CVE-2026-95387: SPDY Dissector Denial of Service (HIGH Severity, CVSS: 8.1) | Sceawere