CVE-2025-11626: Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
Published Oct 10, 2025
·Updated
MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service
Affected Software
3 affected components
Wireshark Wireshark>=4.4.0<=4.4.9, >=4.2.0<=4.2.13
Wireshark Wireshark>=4.2.0<4.2.14
Wireshark Wireshark>=4.4.0<4.4.10
Remediation
Information
Upgrade to version 4.4.10, 4.2.14, or above
Event History
Oct 10, 2025
CVE Published
via MITRE·10:33 PM
Data Sourced
via MITRE·10:33 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-11626?
CVE-2025-11626 has a moderate severity level due to its potential to cause denial of service.
2
How do I fix CVE-2025-11626?
To fix CVE-2025-11626, update Wireshark to version 4.4.10 or later, or 4.2.14 or later.
3
What impact does CVE-2025-11626 have on affected versions of Wireshark?
CVE-2025-11626 allows an infinite loop in the MONGO dissector, resulting in a denial of service.
4
Which versions of Wireshark are affected by CVE-2025-11626?
CVE-2025-11626 affects Wireshark versions from 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13.
5
Is there a workaround for CVE-2025-11626 until I can update Wireshark?
Currently, there are no specific workarounds for CVE-2025-11626 other than updating to a patched version.