Stack-based Buffer Overflow in Junos OS Packet Forwarding Engine
CVE-2026-21903
Key Information:
- Vendor
Juniper Networks
- Status
- Vendor
- CVE Published:
- 15 January 2026
Badges
What is CVE-2026-21903?
A stack-based buffer overflow vulnerability in Juniper Networks' Junos OS affects the Packet Forwarding Engine (PFE). This vulnerability allows an authenticated network-based attacker with low privileges to induce a Denial-of-Service (DoS) by subscribing to telemetry sensors at scale. This action leads to the dropping of all FPC connections, ultimately resulting in an FPC crash and restart. Notably, the issue does not manifest when YANG packages for the specific sensors are installed, highlighting specific use cases that may mitigate the impact. The affected versions of Junos OS include all versions prior to 22.4R3-S7, 23.2 versions before 23.2R2-S4, and 23.4 versions prior to 23.4R2.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Junos OS 0 < 22.4R3-S7
Junos OS 23.2 < 23.2R2-S4
Junos OS 23.4 < 23.4R2
References
CVSS V4
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved