CVE-2026-33797: Junos OS and Junos OS Evolved: An attacker sending a specific genuine BGP packet causes a BGP reset
An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a specific genuine BGP packet in an already established BGP session to reset only that session causing a Denial of Service (DoS).
An attacker repeatedly sending the packet will sustain the Denial of Service (DoS).This issue affects Junos OS:
25.2 versions before 25.2R2
This issue does not affect Junos OS versions before 25.2R1.
This issue affects Junos OS Evolved: 25.2-EVO versions before 25.2R2-EVO
This issue does not affect Junos OS Evolved versions before 25.2R1-EVO.
eBGP and iBGP are affected. IPv4 and IPv6 are affected.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33797?
CVE-2026-33797 is categorized as a high severity vulnerability due to its potential impact on network stability.
How do I fix CVE-2026-33797?
To fix CVE-2026-33797, upgrade to Junos OS version 25.2R2 or higher and Junos OS Evolved version 25.2R2-EVO or higher.
What types of systems are affected by CVE-2026-33797?
CVE-2026-33797 affects Juniper Networks Junos OS and Junos OS Evolved systems running specific vulnerable versions.
What is the nature of the vulnerability in CVE-2026-33797?
CVE-2026-33797 is an Improper Input Validation vulnerability that allows attackers to send a specific BGP packet causing a BGP reset.
Who can exploit CVE-2026-33797?
CVE-2026-33797 can be exploited by unauthenticated, adjacent attackers who can send malicious BGP packets to vulnerable systems.