Executive brief
A vulnerability in Juniper Networks Junos OS can allow an unauthenticated attacker to crash the networking equipment, leading to a complete service outage. This affects MX Series and SRX Series devices when specific security features like anti-malware or web filtering are enabled. The system will automatically attempt to recover, but operations will be disrupted until the restart is complete.
Technical details
An Improper Validation of Specified Quantity in Input vulnerability (CWE-1284) exists in the TCP proxy plugin of Juniper Networks Junos OS. The flaw is triggered when the TCP proxy is engaged for flow sessions supporting ALGs, Advanced Anti-Malware, ICAP, or UTM. A network-based attacker can send a TCP packet with a specifically malformed TCP header, causing the flow processing daemon (flowd) to crash and restart. This results in a complete Denial of Service (DoS) until the daemon recovers. The issue affects MX Series with SPC3 and SRX Series devices running versions 23.4, 24.2, 24.4, and 25.2. Fixes are available in updated Junos OS releases.
Affected products
- Juniper Networks Junos OS 23.4 versions before 23.4R2-S7, 24.2 versions before 24.2R2-S4, 24.4 versions before 24.4R2-S3, 25.2 versions before 25.2R2
Timeline
- 2026-07-09: advisory: Initial publication of JSA110083 / CVE-2026-57023