← Vulnerability feed

Vulnerability record · CVE-2025-52986 · published 11 July 2025

CVE-2025-52986: Juniper junos memory leak vulnerability

Juniper · Junos

A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low privileged user to cause an impact to the availability of the device. When RIB sharding is enabled and a user executes one of several routing related 'show' commands, a certain amount of memory is leaked. When all available memory has been consumed rpd will crash and restart. The leak can be monitored with the CLI command: show task memory detail | match task_shard_mgmt_cookie where the allocated memory in bytes can be seen to continuously increase with each exploitation. This issue affects: Junos OS: * all versions before 21.2R3-S9, * 21.4 versions before 21.4R3-S11, * 22.2 versions before 22.2R3-S7, * 22.4 versions before 22.4R3-S7, * 23.2 versions before 23.2R2-S4,  * 23.4 versions before 23.4R2-S4, * 24.2 versions before 24.2R2, * 24.4 versions before 24.4R1-S2, 24.4R2; Junos OS Evolved: * all versions before 22.2R3-S7-EVO * 22.4-EVO versions before 22.4R3-S7-EVO, * 23.2-EVO versions before 23.2R2-S4-EVO, * 23.4-EVO versions before 23.4R2-S4-EVO, * 24.2-EVO versions before 24.2R2-EVO,  * 24.4-EVO versions before 24.4R2-EVO.

6.8 CVSS 4.0 Medium EPSS 0.12% · top 98.3% CWE-401 · Memory leak
6.8CVSS 4.0 base score
0.12%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low privileged user to cause an impact to the availability of the device. When RIB sharding is enabled and a user executes one of several routing related 'show' commands, a certain amount of memory is leaked. When all available memory has been consumed rpd will crash and restart. The leak can be monitored with the CLI command: show task memory detail | match task_shard_mgmt_cookie where the allocated memory in bytes can be seen to continuously increase with each exploitation. This issue affects: Junos OS: * all versions before 21.2R3-S9, * 21.4 versions before 21.4R3-S11, * 22.2 versions before 22.2R3-S7, * 22.4 versions before 22.4R3-S7, * 23.2 versions before 23.2R2-S4,  * 23.4 versions before 23.4R2-S4, * 24.2 versions before 24.2R2, * 24.4 versions before 24.4R1-S2, 24.4R2; Junos OS Evolved: * all versions before 22.2R3-S7-EVO * 22.4-EVO versions before 22.4R3-S7-EVO, * 23.2-EVO versions before 23.2R2-S4-EVO, * 23.4-EVO versions before 23.4R2-S4-EVO, * 24.2-EVO versions before 24.2R2-EVO,  * 24.4-EVO versions before 24.4R2-EVO.

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-52986 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-36845Juniper Junos OS J-Web PHP variable modification RCEJ-Web in Junos OS on EX Series and SRX Series mishandles the PHP PHPRC environment variable, letting a crafted request alter the PHP execution enviro…KEVEPSS 95%analysed9.8CVE-2020-1631Juniper Junos OS J-Web HTTP service path traversal and local file inclusionThe HTTP/HTTPS service behind J-Web, Web Authentication, Dynamic-VPN, Firewall Authentication Pass-Through with Web-Redirect, and ZTP in Junos OS doe…KEVEPSS 4.8%analysed6.7CVE-2025-21590Juniper Junos OS kernel improper isolation allows local code injectionJunos OS contains an improper isolation or compartmentalization flaw in the kernel that lets a local attacker with shell access inject arbitrary code…KEVEPSS 1.7%analysed5.3CVE-2023-36851Juniper Junos OS SRX J-Web missing authentication allows file upload/downloadJunos OS on SRX Series exposes webauth_operation.php without authentication, letting a network attacker upload and download arbitrary files through J…KEVEPSS 1.1%analysed5.3CVE-2023-36846Juniper Junos OS SRX J-Web Missing Authentication Allows File UploadJunos OS on SRX Series fails to require authentication for a critical function in user.php reachable through J-Web, letting an unauthenticated networ…KEVEPSS 93%analysed5.3CVE-2023-36844Juniper Junos OS EX Series J-Web PHP Environment Variable ModificationJ-Web on Junos OS for EX Series fails to properly restrict external PHP variable modification, letting an unauthenticated network attacker alter impo…KEVEPSS 90%analysed5.3CVE-2023-36847Juniper Junos OS EX Series J-Web installAppPackage.php missing authenticationJunos OS on EX Series exposes installAppPackage.php through J-Web without requiring authentication. An unauthenticated network attacker can upload ar…KEVEPSS 83%analysed10.0CVE-2021-31384Juniper junos improper authorization vulnerabilityDue to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in …EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2025-52986), CISA KEV, FIRST EPSS (scores of 2026-10-05). This page is refreshed as NVD updates the record.