Stack-based Buffer Overflow in Junos OS Packet Forwarding Engine
CVE-2026-21903

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
15 January 2026

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2026-21903?

A stack-based buffer overflow vulnerability in Juniper Networks' Junos OS affects the Packet Forwarding Engine (PFE). This vulnerability allows an authenticated network-based attacker with low privileges to induce a Denial-of-Service (DoS) by subscribing to telemetry sensors at scale. This action leads to the dropping of all FPC connections, ultimately resulting in an FPC crash and restart. Notably, the issue does not manifest when YANG packages for the specific sensors are installed, highlighting specific use cases that may mitigate the impact. The affected versions of Junos OS include all versions prior to 22.4R3-S7, 23.2 versions before 23.2R2-S4, and 23.4 versions prior to 23.4R2.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Junos OS 0 < 22.4R3-S7

Junos OS 23.2 < 23.2R2-S4

Junos OS 23.4 < 23.4R2

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.