Junglewise Threat Intelligence

CVE-2026-57019: Juniper Networks Junos OS DoS in Packet Forwarding Engine on MX Series

CVE-2026-57019 · Severity: medium · CVSS 6.5 · Published 2026-07-09

Vendors: Juniper Networks.

Executive brief

A vulnerability in Juniper Networks MX Series routers can allow an attacker on the same local network to crash the device's packet forwarding engine. These routers are critical infrastructure components used to direct high volumes of network traffic. An exploit would cause a temporary service outage and disrupt network connectivity until the hardware component automatically restarts.

Technical details

An Improper Validation of Specified Quantity in Input vulnerability (CWE-1284) exists in the Packet Forwarding Engine (PFE) of Junos OS on MX Series devices. The root cause is an incorrect calculation of packet size when receiving specific packets from a device within the same broadcast domain, particularly in MAP-T or non-IP traffic encapsulated in IP (such as MPLS over GRE). This miscalculation triggers a Flexible PIC Concentrator (FPC) major error (MQSS_CMERROR_LI_INT_REG_UNROLL_TAIL_LENGTH_OVF), leading to an automatic FPC reset. An unauthenticated, adjacent attacker can exploit this to cause a Denial-of-Service. Patches are available in various Junos OS maintenance releases.

Affected products

  • Juniper Networks Junos OS All versions before 23.2R2-S6, 23.4 versions before 23.4R2-S7, 24.2 versions before 24.2R2-S4, 24.4 versions before 24.4R2-S4, 25.2 versions before 25.2R2

Timeline

  • 2026-07-09: advisory: Initial publication of JSA110079 / CVE-2026-57019

References