CVE-2026-21917: Junos OS: SRX Series: Specifically malformed SSL packet causes FPC crash
An Improper Validation of Syntactic Correctness of Input vulnerability in the Web-Filtering module of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).
If an SRX device configured for UTM Web-Filtering receives a specifically malformed SSL packet, this will cause an FPC crash and restart. This issue affects Junos OS on SRX Series:
23.2 versions from 23.2R2-S2 before 23.2R2-S5, 23.4 versions from 23.4R2-S1 before 23.4R2-S5, 24.2 versions before 24.2R2-S2, 24.4 versions before 24.4R1-S3, 24.4R2.
Earlier versions of Junos are also affected, but no fix is available.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21917?
CVE-2026-21917 is rated as a high severity vulnerability due to its potential to cause a Denial-of-Service (DoS) attack.
How do I fix CVE-2026-21917?
To fix CVE-2026-21917, upgrade the Junos OS to a version that is not affected, specifically above 23.2R2-S5, 23.4R2-S5, or 24.4R2.
Who is affected by CVE-2026-21917?
CVE-2026-21917 affects Juniper Networks Junos OS on SRX Series devices running specific versions between 23.2R2-S2 and 24.4R2.
What kind of attack does CVE-2026-21917 enable?
CVE-2026-21917 allows an unauthenticated, network-based attacker to perform a Denial-of-Service (DoS) attack by exploiting malformed SSL packets.
Is CVE-2026-21917 easy to exploit?
Yes, CVE-2026-21917 is considered easy to exploit due to its reliance on malformed SSL packets and lack of authentication.