CVE-2026-57026

HIGH

Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP invite causes a flowd crash

Title source: cna
STIX 2.1

Description

An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).If the SIP ALG is enabled on an affected device, the processing of a malformed SIP invite packet will cause a flow processing daemon (flowd) crash and restart. This leads to a complete service outage until the system has automatically recovered. This issue affects Junos OS on MX Series with SPC3 and SRX Series: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S5, * 24.4 versions before 24.4R2-S4, * 25.2 versions before 25.2R2, * 25.4 versions before 25.4R1-S2.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory
https://supportportal.juniper.net/JSA110086

Scores

CVSS v3 7.5
EPSS 0.0033
EPSS Percentile 25.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-1286
Status published
Products (9)
juniper/junos 23.2 (11 CPE variants)
juniper/junos 23.4 (12 CPE variants)
juniper/junos 24.2 (9 CPE variants)
juniper/junos 24.4 (8 CPE variants)
juniper/junos 25.2 (4 CPE variants)
juniper/junos 25.4 (3 CPE variants)
juniper/junos < 23.2
Juniper Networks/Junos OS < 23.2R2-S7
Juniper Networks/Junos OS 23.4 - 23.4R2-S8
Published Jul 09, 2026
Tracked Since Jul 10, 2026