Junglewise Threat Intelligence

CVE-2026-57026: Juniper Networks Junos OS DoS in SIP plugin

CVE-2026-57026 · Severity: high · CVSS 7.5 · Published 2026-07-09

Vendors: Juniper Networks.

Executive brief

A vulnerability in Juniper Networks Junos OS can allow an attacker to crash the networking software on certain high-performance routers and firewalls. This occurs when the device processes a specifically crafted SIP (Session Initiation Protocol) message, which is commonly used for voice and video calls. An exploit results in a complete service outage, disrupting all network traffic until the system automatically restarts.

Technical details

An improper validation of syntactic correctness (CWE-1286) exists in the SIP Application Layer Gateway (ALG) plugin of Juniper Networks Junos OS. The vulnerability is triggered when the SIP ALG is enabled and the device processes a malformed SIP INVITE packet. A remote, unauthenticated attacker can exploit this to cause the flow processing daemon (flowd) to crash and restart. This results in a complete denial-of-service for all traffic passing through the affected MX Series (with SPC3) or SRX Series device. Fixed versions have been released across multiple Junos OS release trains.

Affected products

  • Juniper Networks Junos OS All versions before 23.2R2-S7, 23.4 versions before 23.4R2-S8, 24.2 versions before 24.2R2-S5, 24.4 versions before 24.4R2-S4, 25.2 versions before 25.2R2, 25.4 versions before 25.4R1-S2

Timeline

  • 2026-07-09: advisory: Initial publication of JSA110086

References