Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🛡️
Not in CISA KEV
HIGH severity

CVE-2026-95387

HIGH

CVE-2026-95387 is a high-severity (CVSS 8.1) : Heap-based Buffer Overflow vulnerability. No vendor fix is recorded yet; mitigation options are listed below.

SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Published
Updated
Affected
—
Patched
—
Exploits
None indexed
Exploitation data as of Sep 29, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Description

SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Detection & mitigation playbook

Vulnerability
  1. Detect

    Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).

  2. Remediation status

    No fixed release is recorded for CVE-2026-95387 yet. Track the upstream advisory, and apply the exposure-reduction steps below in the meantime.

  3. Mitigate without a patch

    Constrain what reaches the vulnerable code: limit the size and shape of untrusted input, isolate the affected component in a sandboxed or least-privileged process, and enable the platform's memory-safety mitigations (ASLR, stack protector, hardened allocator) so an out-of-bounds access is more likely to fail closed than to be exploitable.

Fixing This On Your OS

If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.

Red HatImportant
Workaround published by Red Hat
Disable the SPDY protocol dissector in Wireshark or TShark to prevent processing of the vulnerable protocol format. For TShark command-line usage, pass the protocol disable flag: ``` tshark --disable-protocol spdy -r <capture_file> ``` For persistent configuration across sessions, append the protocol to the disabled protocols file: ``` echo "spdy" >> ~/.config/wireshark/disabled_protos ``` In the Wireshark graphical interface: 1. Navigate to Analyze -> Enabled Protocols... 2. Search for "SPDY" and clear the checkbox. 3. Click OK or Save. Caveat: Disabling the dissector prevents the decoding and inspection of SPDY protocol streams, treating them as generic TCP or TLS payload. Wireshark must…
Source: Red Hat security advisory for CVE-2026-95387 (CC BY 4.0)

Frequently Asked Questions

SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
O3 Security · Impact-Aware SCA

Is CVE-2026-95387 in your dependencies?

Find it across , including transitive dependencies.

CVE-2026-95387: Memory Corruption (High 8.1)