← Vulnerability feed

Vulnerability record · CVE-2026-21905 · published 15 January 2026

CVE-2026-21905: Juniper junos vulnerability

Juniper · Junos

A Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the SIP application layer gateway (ALG) of Juniper Networks Junos OS on SRX Series and MX Series with MX-SPC3 or MS-MPC allows an unauthenticated network-based attacker sending specific SIP messages over TCP to crash the flow management process, leading to a Denial of Service (DoS). On SRX Series, and MX Series with MX-SPC3 or MS-MPC service cards, receipt of multiple SIP messages causes the SIP headers to be parsed incorrectly, eventually causing a continuous loop and leading to a watchdog timer expiration, crashing the flowd process on SRX Series and MX Series with MX-SPC3, or mspmand process on MX Series with MS-MPC. This issue only occurs over TCP. SIP messages sent over UDP cannot trigger this issue. This issue affects Junos OS on SRX Series and MX Series with MX-SPC3 and MS-MPC: * all versions before 21.2R3-S10,  * from 21.4 before 21.4R3-S12,  * from 22.4 before 22.4R3-S8,  * from 23.2 before 23.2R2-S5,  * from 23.4 before 23.4R2-S6,  * from 24.2 before 24.2R2-S3,  * from 24.4 before 24.4R2-S1,  * from 25.2 before 25.2R1-S1, 25.2R2.

8.7 CVSS 4.0 High EPSS 0.42% · top 66.6% CWE-835 · CWE-835
8.7CVSS 4.0 base score
0.42%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the SIP application layer gateway (ALG) of Juniper Networks Junos OS on SRX Series and MX Series with MX-SPC3 or MS-MPC allows an unauthenticated network-based attacker sending specific SIP messages over TCP to crash the flow management process, leading to a Denial of Service (DoS). On SRX Series, and MX Series with MX-SPC3 or MS-MPC service cards, receipt of multiple SIP messages causes the SIP headers to be parsed incorrectly, eventually causing a continuous loop and leading to a watchdog timer expiration, crashing the flowd process on SRX Series and MX Series with MX-SPC3, or mspmand process on MX Series with MS-MPC. This issue only occurs over TCP. SIP messages sent over UDP cannot trigger this issue. This issue affects Junos OS on SRX Series and MX Series with MX-SPC3 and MS-MPC: * all versions before 21.2R3-S10,  * from 21.4 before 21.4R3-S12,  * from 22.4 before 22.4R3-S8,  * from 23.2 before 23.2R2-S5,  * from 23.4 before 23.4R2-S6,  * from 24.2 before 24.2R2-S3,  * from 24.4 before 24.4R2-S1,  * from 25.2 before 25.2R1-S1, 25.2R2.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-21905 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-36845Juniper Junos OS J-Web PHP variable modification RCEJ-Web in Junos OS on EX Series and SRX Series mishandles the PHP PHPRC environment variable, letting a crafted request alter the PHP execution enviro…KEVEPSS 95%analysed9.8CVE-2020-1631Juniper Junos OS J-Web HTTP service path traversal and local file inclusionThe HTTP/HTTPS service behind J-Web, Web Authentication, Dynamic-VPN, Firewall Authentication Pass-Through with Web-Redirect, and ZTP in Junos OS doe…KEVEPSS 4.8%analysed6.7CVE-2025-21590Juniper Junos OS kernel improper isolation allows local code injectionJunos OS contains an improper isolation or compartmentalization flaw in the kernel that lets a local attacker with shell access inject arbitrary code…KEVEPSS 1.7%analysed5.3CVE-2023-36851Juniper Junos OS SRX J-Web missing authentication allows file upload/downloadJunos OS on SRX Series exposes webauth_operation.php without authentication, letting a network attacker upload and download arbitrary files through J…KEVEPSS 1.1%analysed5.3CVE-2023-36844Juniper Junos OS EX Series J-Web PHP Environment Variable ModificationJ-Web on Junos OS for EX Series fails to properly restrict external PHP variable modification, letting an unauthenticated network attacker alter impo…KEVEPSS 90%analysed5.3CVE-2023-36846Juniper Junos OS SRX J-Web Missing Authentication Allows File UploadJunos OS on SRX Series fails to require authentication for a critical function in user.php reachable through J-Web, letting an unauthenticated networ…KEVEPSS 93%analysed5.3CVE-2023-36847Juniper Junos OS EX Series J-Web installAppPackage.php missing authenticationJunos OS on EX Series exposes installAppPackage.php through J-Web without requiring authentication. An unauthenticated network attacker can upload ar…KEVEPSS 83%analysed10.0CVE-2021-31384Juniper junos improper authorization vulnerabilityDue to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in …EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2026-21905), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.