CVE-2026-21905: Junos OS: SRX Series, MX Series with MX-SPC3 or MS-MPC: Receipt of multiple specific SIP messages results in flow management process crash
A Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the SIP application layer gateway (ALG) of Juniper Networks Junos OS on SRX Series and MX Series with MX-SPC3 or MS-MPC allows an unauthenticated network-based attacker sending specific SIP messages over TCP to crash the flow management process, leading to a Denial of Service (DoS).
On SRX Series, and MX Series with MX-SPC3 or MS-MPC service cards, receipt of multiple SIP messages causes the SIP headers to be parsed incorrectly, eventually causing a continuous loop and leading to a watchdog timer expiration, crashing the flowd process on SRX Series and MX Series with MX-SPC3, or mspmand process on MX Series with MS-MPC.
This issue only occurs over TCP. SIP messages sent over UDP cannot trigger this issue.
This issue affects Junos OS on SRX Series and MX Series with MX-SPC3 and MS-MPC:
all versions before 21.2R3-S10, from 21.4 before 21.4R3-S12, from 22.4 before 22.4R3-S8, from 23.2 before 23.2R2-S5, from 23.4 before 23.4R2-S6, from 24.2 before 24.2R2-S3, from 24.4 before 24.4R2-S1, from 25.2 before 25.2R1-S1, 25.2R2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21905?
CVE-2026-21905 has a critical severity rating due to the risk of system crashes in Junos OS.
How do I fix CVE-2026-21905?
To fix CVE-2026-21905, you should update to the recommended versions of Junos OS as per the guidance from Juniper Networks.
What systems are affected by CVE-2026-21905?
CVE-2026-21905 affects Juniper Networks Junos OS on SRX Series and MX Series devices with specific hardware configurations.
What type of vulnerability is CVE-2026-21905?
CVE-2026-21905 is classified as an Infinite Loop vulnerability in the SIP application layer gateway within Junos OS.
What are the consequences of CVE-2026-21905?
The consequences of CVE-2026-21905 include potential system instability and crashes when multiple specific SIP messages are received.