Junglewise Threat Intelligence

CVE-2026-57020: Juniper Networks Junos OS DoS in QFX10000 Packet Forwarding Engine

CVE-2026-57020 · Severity: medium · CVSS 6.5 · Published 2026-07-09

Vendors: Juniper Networks.

Executive brief

A vulnerability in Juniper Networks Junos OS for QFX10000 series switches can allow a nearby attacker to cause a network outage. By sending specific IPv6 traffic, an attacker can trigger an endless data loop that saturates network links. This results in a denial-of-service condition, preventing legitimate business traffic from reaching its destination.

Technical details

An Improper Check for Unusual or Exceptional Conditions (CWE-754) exists in the Packet Forwarding Engine (PFE) of Junos OS on QFX10000 Series switches. In EVPN-VxLAN configurations, IPv6 multicast traffic reaching a non-IRB interface of a spine switch is incorrectly flooded to other spines and all ESI leaf switches. This behavior creates an infinite forwarding loop that saturates network bandwidth. The attack requires the perpetrator to be on the adjacent network (Layer 2) but requires no authentication or user interaction. Patches are available in versions 23.2R2-S7, 23.4R2-S8, 24.2R2-S4, and 24.4R2-S4; versions beyond 24.4 are unaffected as the hardware is no longer supported.

Affected products

  • Juniper Networks Junos OS All versions before 23.2R2-S7, 23.4 versions before 23.4R2-S8, 24.2 versions before 24.2R2-S4, 24.4 versions before 24.4R2-S4

Timeline

  • 2026-07-09: advisory: Initial publication of JSA110080
  • 2026-07-09: disclosed

References