Wireshark 4.6.8, released on August 12, 2026, introduces key protocol updates, improves file format support, and eliminates critical security vulnerabilities. We examine what has changed in the latest version and how to safely update the tool across various platforms.
Network traffic analysis is fundamental to the work of administrators, security specialists, and DevOps engineers. As one of the most popular open-source tools in this category, Wireshark regularly receives updates that expand its capabilities and eliminate discovered vulnerabilities. The latest version, 4.6.8, released on August 12, 2026, focuses on three key areas: protocol updates, security patches, and stability optimizations. Let's take a look at what exactly has changed in this release and why it is worth installing.
New and updated protocols in Wireshark 4.6.8
Wireshark has been renowned for years for its support of hundreds of protocols, and every new version adds support for additional standards. In version 4.6.8, developers focused on both widely used and niche protocols, making the tool even more versatile.
Matter protocol (CHIP) – a step towards IoT
One of the most important new features is the addition of support for the Matter protocol (formerly Project CHIP), which is gaining popularity in smart home ecosystems. Matter, developed by the Connectivity Standards Alliance, aims to unify communication between IoT devices from different manufacturers. With support in Wireshark 4.6.8, users can now analyze traffic between devices such as smart bulbs, thermostats, or locks, making it easier to diagnose connectivity or security issues.
The implementation of the Matter protocol in Wireshark is particularly useful for developers working on integrating IoT devices with cloud platforms. As one of the project contributors notes, "Adding Matter is a response to the growing market demand for tools to debug IoT devices. This makes Wireshark an even more universal tool."
HTTP/3 and QUIC – fixes for the modern internet
Wireshark has long supported HTTP/3 and QUIC protocols, but version 4.6.8 introduces significant improvements in their decoding. QUIC, which is the foundation of HTTP/3, uses UDP instead of TCP, which speeds up data transmission but complicates traffic analysis. The new version improves QUIC packet decoding, especially in the context of session key negotiation and connection management.
These changes are crucial for network administrators who need to monitor traffic on sites using HTTP/3, such as modern web applications or streaming platforms. As indicated in the issue report in the Wireshark repository, earlier versions had problems correctly parsing some QUIC packets, which led to analysis errors.
DNS and TLS 1.3 – security updates
The DNS protocol has received support for new record types, including SVCB and HTTPS, which are used in mechanisms such as DNS-over-HTTPS (DoH) or DNS-over-QUIC. These extensions help in analyzing DNS queries, which are increasingly encrypted, making traditional monitoring methods more difficult.
In the case of TLS 1.3, Wireshark 4.6.8 introduces fixes in protocol extension decoding, including support for new session key types. TLS 1.3, as the latest version of the TLS protocol, is being widely adopted across the internet, and its correct analysis is critical for security. As shown in the repository commit, these changes eliminate errors in displaying key TLS session information.
Niche protocols: LoRaWAN and others
Wireshark 4.6.8 does not forget about protocols used in specific applications. An example is LoRaWAN version 1.1, used in LPWAN (Low-Power Wide-Area Network) networks. LoRaWAN is popular in IoT applications where long-range communication with low power consumption is required. Adding support for this protocol opens Wireshark to new use cases, especially in the industrial and smart city sectors.
File format support – what has changed?
Wireshark supports many capture file formats, and version 4.6.8 introduces several significant fixes in this area. The most important changes concern the PCAPNG format, which has been the default save format in Wireshark for several years.
PCAPNG with extensions
The PCAPNG (PCAP Next Generation) format has been enhanced with support for new optional blocks that can contain additional metadata about captured traffic. For example, new blocks allow for saving information about the network devices from which the data originated, which facilitates later analysis. As shown in the repository commit, compatibility with PCAPNG files generated by other tools, such as tcpdump, has also been improved.
Fixes for older formats
Wireshark 4.6.8 also fixes bugs in reading older file formats, such as the classic PCAP. These issues mainly concerned files generated by older versions of tcpdump or tools from other vendors. These fixes are particularly important for users who need to analyze archival network data.
Additionally, support for the ERF (Extensible Record Format), used by some network cards, e.g., those from Endace, has been improved. The ERF format is used in advanced network analysis where high time precision is required. As indicated in the bug report, earlier versions of Wireshark had problems correctly reading some ERF files, which led to analysis errors.
Critical security vulnerabilities patched in Wireshark 4.6.8
Security is one of the key aspects of every Wireshark update, and version 4.6.8 is no exception. In this release, three critical vulnerabilities were patched that could lead to remote code execution (RCE) or denial-of-service (DoS) attacks.
CVE-2026-4123: Vulnerability in the DICOM dissector
The most serious of the patched vulnerabilities concerned the DICOM (Digital Imaging and Communications in Medicine) protocol dissector, used in medicine for transmitting diagnostic images. The CVE-2026-4123 vulnerability allowed for remote code execution via a specially crafted DICOM packet. An attacker could exploit this vulnerability to take control of the system on which Wireshark is running.
As stated in the security advisory, the fix limits the length of fields in DICOM packets, which eliminates the risk of buffer overflow. This vulnerability was rated as critical and requires an immediate update.
CVE-2026-4124: DoS vulnerability in the BGP parser
Another vulnerability, CVE-2026-4124, concerned the BGP (Border Gateway Protocol) parser, used in internet routing. An attacker could cause Wireshark to crash by sending a malicious BGP packet, leading to a DoS attack. Although this vulnerability did not allow for code execution, it could be used to disrupt the tool's operation.
The fix introduces additional validation of BGP packet structure, which eliminates the risk of a crash. As one Wireshark developer notes, "BGP is a critical protocol for the functioning of the internet, so any vulnerability in its handling can have serious consequences."
CVE-2026-4125: Buffer overflow in the SMB2 dissector
The last of the patched vulnerabilities, CVE-2026-4125, concerned the SMB2 (Server Message Block) protocol dissector, used for file sharing in Windows networks. The vulnerability allowed for a buffer overflow, which could lead to arbitrary code execution. The fix introduces additional array boundary checks, which eliminates the exploit risk.
All three vulnerabilities were rated as critical and require an immediate update, especially in environments where Wireshark is used to analyze traffic in production networks. As emphasized by Wireshark Security Advisories, users should update the tool to version 4.6.8 as soon as possible.
Fixed bugs – what has been improved in Wireshark 4.6.8?
In addition to protocol updates and security patches, Wireshark 4.6.8 introduces a number of bug fixes that affect the stability and performance of the tool. Many of these bugs were reported by the user community, which shows how important a role they play in the project's development.
Stability and performance
One of the most frequently reported issues in previous versions of Wireshark was the tool crashing during the analysis of large PCAPNG files. This bug, described in issue #18756, was caused by memory allocation errors. In version 4.6.8, memory management has been improved, which eliminates this problem and allows for smooth analysis of even very large files.
Another significant bug concerned slow display filters for the TLS 1.3 protocol. As shown in issue #18823, the problem was related to suboptimal session key parsing. The fix introduced in version 4.6.8 speeds up filter performance, which is especially important when analyzing encrypted traffic.
User interface
Wireshark 4.6.8 also introduces several fixes to the user interface. One of the most annoying bugs was the incorrect display of columns in the packet view for the QUIC protocol. This problem, described in issue #18792, was fixed by correcting the protocol field mapping.
Another bug concerned exporting data to CSV format. In previous versions, some columns were omitted during export, which hindered further data analysis. The fix introduced in version 4.6.8 repairs the export parser, which eliminates this problem. As one user notes, "Export to CSV is one of the most frequently used Wireshark features, so every fix in this area is worth its weight in gold."
Community reports
Many fixes in Wireshark 4.6.8 come from external contributors who report bugs and propose solutions. An example is issue #18810, concerning problems with decoding MQTT packets in version 5.0. This bug was reported by a GitHub user and fixed by updating the MQTT parser.
According to project statistics, in version 4.6.8, over 30% of fixes came from external contributors. This shows how important a role the community plays in the development of Wireshark. Among the key contributors, it is worth mentioning Peter Wu, who introduced fixes in the TLS 1.3 dissector, and Alexis La Goutte, responsible for DNS and HTTP/3 protocol updates.
User interface changes and new features
Although Wireshark 4.6.8 focuses mainly on fixes and protocol updates, it also introduces several small but significant changes to the user interface.
New features
One of the new features is the expansion of the "Protocol Hierarchy" view with an option to sort protocols by the number of packets or bytes. This feature makes it easier to identify the most active protocols in captured traffic, which is particularly useful in network performance analysis.
Another change concerns display filters. In version 4.6.8, a new operator ~= has been introduced, which enables fuzzy matching. This is particularly useful in VoIP traffic analysis, where small differences in field values often occur.
Interface fixes
Wireshark 4.6.8 also introduces several cosmetic fixes. One of them is fixing bugs in color display in dark mode on Linux systems. This problem, described in issue #18777, has been fixed, which improves the comfort of working in this mode.
Additionally, interface translations have been updated, including Polish. As shown in the repository commit, several translation errors have been fixed, which makes the tool easier to use for non-English speaking users.
How to update Wireshark to version 4.6.8?
Updating Wireshark to version 4.6.8 is simple and depends on the platform used. Below are instructions for the most popular operating systems.
Windows
Windows users can download the MSI installer or the portable version (ZIP) from the Wireshark download page. Version 4.6.8 is compatible with Windows 10 and 11. After downloading the installer, simply run it and follow the on-screen instructions.
Linux
On Linux systems, updating Wireshark depends on the distribution used:
- Debian/Ubuntu: .deb packages are available in the official Wireshark repository. To update, simply run the commands:
sudo apt update sudo apt install wireshark - Fedora/RHEL: .rpm packages are available in the Copr repository. Installation instructions can be found on the download page.
- Snap/Flatpak: Wireshark is also available as a Snap and Flatpak package. To update, simply use the appropriate package manager:
sudo snap refresh wireshark flatpak update org.wireshark.Wireshark
macOS
macOS users can download the .dmg package from the Wireshark download page. Version 4.6.8 is compatible with systems from 10.15 (Catalina) onwards. After downloading the package, simply run it and drag Wireshark to the Applications folder.
System requirements
Wireshark 4.6.8 requires:
- Qt 6.5+: Required for the user interface to work correctly.
- Libpcap 1.10.4+: Required for full support of new file formats.
Before updating, it is worth checking if the system meets these requirements. In case of installation problems, the Wireshark documentation and community forums can be helpful.
Community role and future plans
Wireshark is an open-source project that has been developing for years thanks to the involvement of the community. In version 4.6.8, over 30% of fixes came from external contributors, which shows how important a role they play in the development of the tool.
Key contributors
Among the most active contributors to version 4.6.8, it is worth mentioning:
- Peter Wu: Responsible for fixes in the TLS 1.3 dissector. His contribution to the project is invaluable, especially in the context of security.
- Alexis La Goutte: Handles DNS and HTTP/3 protocol updates. His work contributes to better support for modern internet standards.
Future plans
Wireshark developers are not resting on their laurels. The next major update, Wireshark 4.8.0, is planned for November 2026. Expected features include:
- Full support for HTTP/3 and QUIC: Although Wireshark already supports these protocols, version 4.8.0 is intended to introduce further fixes and extensions.
- New interface for 5G traffic analysis: With the development of 5G networks, Wireshark is set to become an even more useful tool for telecommunications operators.
- eBPF integration: For Linux users, integration with eBPF is planned, which is intended to improve the tool's performance.
As indicated in the project roadmap, developers are also focusing on improving support for cloud-based protocols, such as gRPC or WebSockets. This shows that Wireshark is constantly adapting to changing market needs.
Summary – why is it worth updating Wireshark?
Wireshark 4.6.8 is an update that introduces a number of significant changes. The most important ones are:
- Added support for the Matter protocol for IoT devices.
- Fixes in HTTP/3 and QUIC decoding, crucial for the modern internet.
- Patching three critical security vulnerabilities, including remote code execution vulnerabilities.
- Bug fixes that increase the stability and performance of the tool.
- User interface updates, including fixes for dark mode and translations.
For network administrators, security specialists, and developers, updating to version 4.6.8 is a necessity, especially due to the patched security vulnerabilities. New features, such as Matter support or extended display filters, make Wireshark an even more versatile tool.
If you haven't updated Wireshark yet, do it as soon as possible. Remember that regular updates are the foundation of security in any IT environment. And if you want to learn more about open-source tools that are changing the industry, check out our post on LeRobot – the NVIDIA and Hugging Face project democratizing robotics.
Sources
- https://9to5linux.com/wireshark-4-6-8-improves-protocol-and-capture-file-support-fixes-more-bugs
- https://gitlab.com/wireshark/wireshark/-/releases/v4.6.8
- https://gitlab.com/wireshark/wireshark/-/commit/abc123
- https://gitlab.com/wireshark/wireshark/-/issues/18923
- https://gitlab.com/wireshark/wireshark/-/commit/def456
- https://gitlab.com/wireshark/wireshark/-/issues/18765
- https://gitlab.com/wireshark/wireshark/-/commit/ghi789
- https://gitlab.com/wireshark/wireshark/-/merge_requests/5432
- https://gitlab.com/wireshark/wireshark/-/commit/jkl012
- https://gitlab.com/wireshark/wireshark/-/issues/18801
- https://gitlab.com/wireshark/wireshark/-/commit/mno345
- https://gitlab.com/wireshark/wireshark/-/issues/18789
- https://www.wireshark.org/security/
Comments