CVE-2026-57021
Analyzed Analyzed - Analysis Complete

Out-of-bounds Write in Juniper Networks Junos OS SRX Series

Vulnerability report for CVE-2026-57021, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-09

Last updated on: 2026-07-13

Assigner: Juniper Networks, Inc.

Description

An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an SRX Series device is configured for remote-access VPN with pre-logon compliance check, a network-based attacker sending specifically formatted requests can trigger an out of bounds write leading to an http-gk process crash. This crash leads to unavailability of all services depending on the [ system services web-management ] configuration (like J-Web, remote access VPN and firewall authentication) until the process automatically restarts. This issue affectsΒ Junos OS on SRX Series: * 23.2 versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2-S4, * 25.2 versions before 25.2R2, * 25.4 versions before 25.4R1-S1, 25.4R2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-09
Last Modified
2026-07-13
Generated
2026-07-31
AI Q&A
2026-07-10
EPSS Evaluated
2026-07-30
NVD
EUVD

Affected Vendors & Products

Showing 45 associated CPEs
Vendor Product Version / Range
juniper junos 23.2
juniper junos 23.2
juniper junos 23.2
juniper junos 23.2
juniper junos 23.4
juniper junos 23.4
juniper junos 23.4
juniper junos 23.2
juniper junos 24.2
juniper junos 24.2
juniper junos 23.4
juniper junos 23.2
juniper junos 23.2
juniper junos 23.4
juniper junos 23.4
juniper junos 23.4
juniper junos 23.4
juniper junos 24.2
juniper junos 24.2
juniper junos 23.2
juniper junos 23.2
juniper junos 23.4
juniper junos 24.2
juniper junos 24.4
juniper junos 24.4
juniper junos 24.4
juniper junos 24.4
juniper junos 24.2
juniper junos 24.4
juniper junos 23.4
juniper junos 24.2
juniper junos 24.4
juniper junos 25.2
juniper junos 25.2
juniper junos 25.2
juniper junos 25.2
juniper junos 23.2
juniper junos 23.4
juniper junos 24.2
juniper junos 24.4
juniper junos 23.2
juniper junos 23.4
juniper junos 24.4
juniper junos 25.4
juniper junos 25.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Out-of-bounds Write in the http-gatekeeper (http-gk) component of Juniper Networks Junos OS on SRX Series devices. It allows an unauthenticated attacker on the network to send specially crafted requests that cause the http-gk process to crash.

The crash occurs when the device is configured for remote-access VPN with pre-logon compliance check enabled. The out-of-bounds write leads to a denial of service by making services dependent on the system services web-management configuration unavailable until the process restarts.

Impact Analysis

The primary impact of this vulnerability is a Denial-of-Service (DoS) condition. An attacker can cause the http-gk process to crash, which results in the unavailability of critical services such as J-Web, remote access VPN, and firewall authentication.

These services remain unavailable until the http-gk process automatically restarts, potentially disrupting network management and remote access capabilities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57021. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart