CVE-2026-96419
Received Received - Intake

Profile Import Crash in GitLab Allows DoS and Code Execution

Vulnerability report for CVE-2026-96419, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: GitLab Inc.

Description

Profile import crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service and possible code execution

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
gitlab profile_import From 4.6.0 (inc) to 4.6.8 (inc)
gitlab profile_import From 4.4.0 (inc) to 4.4.18 (inc)
wireshark wireshark From 4.6.0 (inc) to 4.6.8 (inc)
wireshark wireshark From 4.4.0 (inc) to 4.4.18 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-96419 is a bypass of a previous patch in Wireshark affecting Windows systems. It allows malicious ZIP files to bypass path traversal containment checks due to a platform-specific code guard. This enables writing arbitrary files to the Wireshark plugins directory, which can execute arbitrary code when Wireshark restarts.

Detection Guidance

Check Wireshark version with 'wireshark -v'. If running 4.6.0-4.6.8 or 4.4.0-4.4.18 on Windows, the system is vulnerable. Inspect ZIP files imported via profile import for path traversal sequences like '../../'. Monitor %APPDATA%\Wireshark\plugins\ for unexpected Lua files.

Impact Analysis

An attacker could craft a malicious ZIP file to silently write files to your system during profile import. When Wireshark restarts, it may execute arbitrary code like spawning applications without your knowledge. This requires user interaction to import the malicious profile.

Compliance Impact

This vulnerability could potentially violate compliance with GDPR and HIPAA by allowing arbitrary code execution on affected systems. The ability to write malicious files to restricted directories and execute code without user awareness undermines data protection and integrity requirements. GDPR's principle of security and confidentiality could be compromised if personal data is exposed or altered. HIPAA's integrity and availability requirements may also be impacted if unauthorized code execution disrupts systems handling protected health information.

Mitigation Strategies

Upgrade Wireshark to version 4.6.9, 4.4.19, or later immediately. Avoid importing untrusted configuration profiles. Remove any suspicious Lua files from the plugins directory. Ensure the path traversal fix is applied universally across all platforms.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-96419. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart