CVE-2026-33797

Severity CVSS v4.0:
HIGH
Type:
CWE-20 Input Validation
Publication date:
09/04/2026
Last modified:
09/04/2026

Description

An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a specific genuine BGP packet in an already established BGP session to reset only that session causing a Denial of Service (DoS).<br /> <br /> An attacker repeatedly sending the packet will sustain the Denial of Service (DoS).This issue affects Junos OS:<br /> <br /> * 25.2 versions before 25.2R2<br /> <br /> <br /> This issue doesn&amp;#39;t not affected Junos OS versions before 25.2R1.<br /> <br /> This issue affects Junos OS Evolved: <br /> * 25.2-EVO versions before 25.2R2-EVO<br /> <br /> <br /> This issue doesn&amp;#39;t not affected Junos OS Evolved versions before 25.2R1-EVO.<br /> <br /> eBGP and iBGP are affected.<br /> IPv4 and IPv6 are affected.

References to Advisories, Solutions, and Tools