CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
zetlyn/cve-ghsa vulnerability ghsa GHSA-jp3x-6949-38v9 cve CVE-2026-95393 known 2026-09-29
https://github.com/advisories/GHSA-jp3x-6949-38v9
Properties
| cvss | 4.7receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-95393",
"cvss": {
"score": 4.7,
"vector_string": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
"cvss_severities": {
"cvss_v3": {
"score": 4.7,
"vector_string": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-122",
"name": "Heap-based Buffer Overflow"
}
],
"description": "CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service",
"epss": {
"percentage": 0.00128,
"percentile": 0.02056
},
"ghsa_id": "GHSA-jp3x-6949-38v9",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-jp3x-6949-38v9",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-jp3x-6949-38v9"
},
{
"type": "CVE",
"value": "CVE-2026-95393"
}
],
"nvd_published_at": "2026-09-29T10:17:15Z",
"published_at": "2026-09-29T12:31:30Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-95393",
"https://gitlab.com/wireshark/wireshark/-/work_items/21510",
"https://www.wireshark.org/security/wnpa-sec-2026-99.html",
"https://github.com/advisories/GHSA-jp3x-6949-38v9"
],
"repository_advisory_url": null,
"severity": "medium",
"source_code_location": "",
"summary": "CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service",
"type": "unreviewed",
"updated_at": "2026-09-29T12:31:38Z",
"url": "https://api.github.com/advisories/GHSA-jp3x-6949-38v9",
"vulnerabilities": [],
"withdrawn_at": null
} |
|---|---|
| cwe | CWE-122receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-95393",
"cvss": {
"score": 4.7,
"vector_string": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
"cvss_severities": {
"cvss_v3": {
"score": 4.7,
"vector_string": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-122",
"name": "Heap-based Buffer Overflow"
}
],
"description": "CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service",
"epss": {
"percentage": 0.00128,
"percentile": 0.02056
},
"ghsa_id": "GHSA-jp3x-6949-38v9",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-jp3x-6949-38v9",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-jp3x-6949-38v9"
},
{
"type": "CVE",
"value": "CVE-2026-95393"
}
],
"nvd_published_at": "2026-09-29T10:17:15Z",
"published_at": "2026-09-29T12:31:30Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-95393",
"https://gitlab.com/wireshark/wireshark/-/work_items/21510",
"https://www.wireshark.org/security/wnpa-sec-2026-99.html",
"https://github.com/advisories/GHSA-jp3x-6949-38v9"
],
"repository_advisory_url": null,
"severity": "medium",
"source_code_location": "",
"summary": "CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service",
"type": "unreviewed",
"updated_at": "2026-09-29T12:31:38Z",
"url": "https://api.github.com/advisories/GHSA-jp3x-6949-38v9",
"vulnerabilities": [],
"withdrawn_at": null
} |
| severity | mediumreceipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-95393",
"cvss": {
"score": 4.7,
"vector_string": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
"cvss_severities": {
"cvss_v3": {
"score": 4.7,
"vector_string": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-122",
"name": "Heap-based Buffer Overflow"
}
],
"description": "CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service",
"epss": {
"percentage": 0.00128,
"percentile": 0.02056
},
"ghsa_id": "GHSA-jp3x-6949-38v9",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-jp3x-6949-38v9",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-jp3x-6949-38v9"
},
{
"type": "CVE",
"value": "CVE-2026-95393"
}
],
"nvd_published_at": "2026-09-29T10:17:15Z",
"published_at": "2026-09-29T12:31:30Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-95393",
"https://gitlab.com/wireshark/wireshark/-/work_items/21510",
"https://www.wireshark.org/security/wnpa-sec-2026-99.html",
"https://github.com/advisories/GHSA-jp3x-6949-38v9"
],
"repository_advisory_url": null,
"severity": "medium",
"source_code_location": "",
"summary": "CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service",
"type": "unreviewed",
"updated_at": "2026-09-29T12:31:38Z",
"url": "https://api.github.com/advisories/GHSA-jp3x-6949-38v9",
"vulnerabilities": [],
"withdrawn_at": null
} |
Text
CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service