SIP Application Layer Gateway Vulnerability in Juniper Networks Junos OS
CVE-2026-21905

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
15 January 2026

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2026-21905?

A vulnerability exists in the SIP Application Layer Gateway (ALG) of Juniper Networks' Junos OS that can be exploited by an unauthenticated attacker. By sending specific SIP messages over TCP, the attacker can trigger improper parsing of SIP headers. This mismanagement initiates a continuous loop, resulting in a crash of the flow management process on SRX and MX series devices equipped with certain service cards. Notably, this issue affects only TCP traffic and does not occur with SIP messages sent over UDP. The flow management process crash can lead to a Denial of Service condition, disrupting network operations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Junos OS SRX Series 0 < 21.2R3-S10

Junos OS SRX Series 21.4 < 21.4R3-S12

Junos OS SRX Series 22.4 < 22.4R3-S8

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.