Denial of Service Vulnerability in iperf3 Affects ESnet
CVE-2026-102253

8.7HIGH

Key Information:

Vendor

Esnet

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102253?

iperf3, in versions earlier than 3.22, is susceptible to a denial of service vulnerability that allows remote, unauthenticated attackers to disrupt server functionality. By sending a specifically crafted control-channel parameter message followed by a single 16-byte UDP datagram, attackers can force the server's UDP receive worker into an unrecoverable infinite loop. This causes significant CPU usage, rendering the server inoperable until it is forcibly terminated. The impacted processes do not respond to normal shutdown signals, leading to prolonged downtime.

Affected Version(s)

iperf3 3.14 < 3.22

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ravindu Lakmina Munaweera
VulnCheck
.