CVE-2026-57030: Junos OS: SRX Series: Flow sessions are not getting cleared leading to a DoS

Published Jul 9, 2026
·
Updated

A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

As part of the stateful traffic processing on SRX Series devices flows are being established, and removed when not needed anymore. During the removal process the timeout of a flow should be set to 3 seconds and consequentially the flow should be removed shortly after. Due to a race condition occurring when setting the timeout there is a chance (the exact conditions are outside the attackers control) that the timeout is instead set to a very high value of larger than 10,000 seconds:

user@host> show security flow session | match timeout Session ID: 98784248524, Policy name: PROD-FLOW/4, HA State: Active, Timeout: 85250, Session State: Valid

This will lead to an accumulation of flows which can be observed by an ever-increasing value of invalidated sessions in the output of 'show security flow session summary':

user@host> show security flow session summary | match invalid Invalidated sessions: 216931These sessions can't be cleared manually with the 'clear security flow session' command, which will either lead to forwarding to stop (and the system needs to be manually recovered with a reboot) or to a flowd core and automatic reboot.

This issue affects Junos OS on SRX Series:

24.2 versions before 24.2R2-S3, 24.4 versions before 24.4R2-S1, 24.4R2-S2, 25.2 versions before 25.2R1-S2, 25.2R2.

This issue does not affect releases earlier than 24.2R1;

Affected Software

35 affected components
Juniper Networks Junos OS (SRX Series) - packet forwarding engine (PFE)<24.2R2-S3, <24.4R2-S1, <24.4R2-S2, <25.2R1-S2, <25.2R2, >=24.2R1<24.2R2-S3, >=24.4<24.4R2-S1, >=24.4<24.4R2-S2, >=25.2<25.2R1-S2, >=25.2<=25.2R2
All of the following
Any of the following
Juniper Junos=24.2
Juniper Junos=24.2-r1
Juniper Junos=24.2-r1-s1
Juniper Junos=24.2-r1-s2
Juniper Junos=24.2-r2
Juniper Junos=24.2-r2-s1
Juniper Junos=24.2-r2-s2
Juniper Junos=24.4
Juniper Junos=24.4-r1
Juniper Junos=24.4-r1-s2
Juniper Junos=24.4-r1-s3
Juniper Junos=24.4-r2
Juniper Junos=25.2
Juniper Junos=25.2-r1
Juniper Junos=25.2-r1-s1
Any of the following
Juniper SRX1500
Juniper SRX1600
Juniper SRX2300
Juniper SRX300
Juniper SRX320
Juniper SRX340
Juniper SRX345
Juniper Srx380
Juniper Srx400
Juniper SRX4100
Juniper Srx4120
Juniper SRX4200
Juniper SRX4300
Juniper Srx440
Juniper SRX4600
Juniper SRX4700
Juniper SRX5400
Juniper SRX5600
Juniper SRX5800

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Juniper Networks Junos OS (SRX Series) to a version that resolves this vulnerability.

    Fixed in 24.2R2-S3
  2. Upgrade

    Upgrade Juniper Networks Junos OS (SRX Series) to a version that resolves this vulnerability.

    Fixed in 24.4R2-S1
  3. Upgrade

    Upgrade Juniper Networks Junos OS (SRX Series) to a version that resolves this vulnerability.

    Fixed in 25.2R1-S2
  4. Upgrade

    Upgrade Juniper Networks Junos OS (SRX Series) to a version that resolves this vulnerability.

    Fixed in 25.2R2
  5. Upgrade

    Upgrade Juniper Networks Junos OS (SRX Series) to a version that resolves this vulnerability.

    Fixed in 25.4R1
  6. Configuration

    Ensure that during the removal process the flow timeout is set to 3 seconds so the flow is removed shortly after (mitigates the race condition where the timeout may be set to >10000 seconds).

    Juniper Networks Junos OS (SRX Series) packet forwarding engine (PFE) Flow timeout on session removal = 3 seconds
  7. Compensating control

    Do not rely on the 'clear security flow session' command to clear invalidated sessions for this issue; it can lead to forwarding stopping or a flowd core and automatic reboot. Instead, prepare for manual recovery (including reboot if needed) after applying the resolved software updates and/or after confirming invalidated sessions and timeouts.

  8. Operational

    Manually recover the SRX device with a reboot if forwarding stops after attempting to clear invalidated sessions (the material states manual recovery with a reboot may be required).

  9. Operational

    Verify mitigation by checking invalidated sessions and flow timeouts using: 'show security flow session summary | match invalid' and 'show security flow session | match timeout' (watch for the ever-increasing 'invalidated sessions' counter described).

Event History

Jul 9, 2026
CVE Published
via MITRE·09:13 PM
Data Sourced
via MITRE·09:13 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:17 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-57030?

The severity of CVE-2026-57030 is rated medium with a score of 5.9.

2

How do I fix CVE-2026-57030?

To fix CVE-2026-57030, update the Junos OS on SRX Series devices to the latest version that addresses the vulnerability.

3

What type of attack does CVE-2026-57030 facilitate?

CVE-2026-57030 allows an unauthenticated attacker to cause a Denial-of-Service (DoS) on affected devices.

4

Which devices are affected by CVE-2026-57030?

CVE-2026-57030 affects devices running Juniper Networks Junos OS on the SRX Series.

5

What component of Junos OS is vulnerable in CVE-2026-57030?

The vulnerability in CVE-2026-57030 is within the packet forwarding engine (PFE) of Junos OS.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203