๐Ÿ›ก๏ธ CVE-2026-21905
๐ŸŸ  CVSS 7.5 โ€” High โœ… No Known Exploit CWE-835 NVD
7.5
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

A Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the SIP application layer gateway (ALG) of Juniper Networks Junos OS on SRX Series and MX Series with MX-SPC3 or MS-MPC allows an unauthenticated network-based attacker sending specific SIP messages over TCP to crash the flow management process, leading to a Denial of Service (DoS). On SRX Series, and MX Series with MX-SPC3 or MS-MPC service cards, receipt of multiple SIP messages causes the SIP headers to be parsed incorrectly, eventually causing a continuous loop and leading to a watchdog timer expiration, crashing the flowd process on SRX Series and MX Series with MX-SPC3, or mspmand process on MX Series with MS-MPC. This issue only occurs over TCP. SIP messages sent over UDP cannot trigger this issue. This issue affects Junos OS on SRX Series and MX Series with MX-SPC3 and MS-MPC: * all versions before 21.2R3-S10,ย  * from 21.4 before 21.4R3-S12,ย  * from 22.4 before 22.4R3-S8,ย  * from 23.2 before 23.2R2-S5,ย  * from 23.4 before 23.4R2-S6,ย  * from 24.2 before 24.2R2-S3,ย  * from 24.4 before 24.4R2-S1,ย  * from 25.2 before 25.2R1-S1, 25.2R2.

Details

Severity HIGH
CVSS Score 7.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE CWE-835
Public Exploit โœ… No
Source NVD
Published 2026-01-15
Updated 2026-06-02
Modified 2026-01-23
Fix URL N/A

Affected Packages

Software From version Fixed in
junos โ€” โ€”

Similar Threats

Free Vulnerability Check

Is your WordPress site affected?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against known CVE records.

Scan My Site Free โ†’

No credit card required  ยท  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.