CVE-2026-21903
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2026-01-15

Last updated on: 2026-01-15

Assigner: Juniper Networks, Inc.

Description
A Stack-based Buffer Overflow vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS allows a network-based attacker, authenticated with low privileges to cause a Denial-of-Service (DoS). Subscribing to telemetry sensors at scale causes all FPC connections to drop, resulting in an FPC crash and restart. The issue was not seen when YANG packages for the specific sensors were installed. This issue affects Junos OS:  * all versions before 22.4R3-S7, * 23.2 version before 23.2R2-S4, * 23.4 versions before 23.4R2.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-15
Last Modified
2026-01-15
Generated
2026-06-16
AI Q&A
2026-01-16
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
juniper_networks junos_os to 22.4R3-S7 (exc)
juniper_networks junos_os to 23.2R2-S4 (exc)
juniper_networks junos_os to 23.4R2 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a stack-based buffer overflow in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS. It allows a network-based attacker with low privileges to cause a Denial-of-Service (DoS) by subscribing to telemetry sensors at scale, which causes all FPC connections to drop, resulting in an FPC crash and restart. The issue does not occur when YANG packages for the specific sensors are installed.

Impact Analysis

The vulnerability can impact you by causing a Denial-of-Service (DoS) condition on affected Junos OS devices. Specifically, subscribing to telemetry sensors at scale can cause all Flexible PIC Concentrator (FPC) connections to drop, leading to an FPC crash and restart, which disrupts network operations.

Mitigation Strategies

To mitigate this vulnerability, you should upgrade Junos OS to a fixed version. Specifically, update to at least version 22.4R3-S7, 23.2R2-S4, or 23.4R2 or later. Additionally, installing the YANG packages for the specific telemetry sensors can prevent the issue from occurring when subscribing to telemetry sensors at scale.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-21903. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart