CVE-2026-33782: Junos OS: MX Series: In specific DHCPv6 scenarios jdhcpd memory increases continuously with subscriber logouts
A Missing Release of Memory after Effective Lifetime vulnerability in the DHCP daemon (jdhcpd) of Juniper Networks Junos OS on MX Series, allows an adjacent, unauthenticated attacker to cause a memory leak, that will eventually cause a complete Denial-of-Service (DoS).
In a DHCPv6 over PPPoE, or DHCPv6 over VLAN with Active lease query or Bulk lease query scenario, every subscriber logout will leak a small amount of memory. When all available memory has been exhausted, jdhcpd will crash and restart which causes a complete service impact until the process has recovered.
The memory usage of jdhcpd can be monitored with:
user@host> show system processes extensive | match jdhcpd
This issue affects Junos OS:
all versions before 22.4R3-S1, 23.2 versions before 23.2R2, 23.4 versions before 23.4R2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33782?
CVE-2026-33782 has a medium severity level due to its potential impact on system performance.
How do I fix CVE-2026-33782?
To fix CVE-2026-33782, upgrade Junos OS on affected MX Series devices to the latest patched version.
Which versions of Junos OS are affected by CVE-2026-33782?
CVE-2026-33782 affects Junos OS versions up to 22.4R3-S1 and specific versions between 23.2 and 23.4.
What kind of attack can CVE-2026-33782 enable?
CVE-2026-33782 can allow an adjacent, unauthenticated attacker to cause excessive memory allocation in the DHCP daemon.
What should I do if I can't upgrade to a patched version for CVE-2026-33782?
If upgrading is not possible, implementing access controls to limit unauthorized access may help mitigate CVE-2026-33782.