Vulnerability Description
An Improper Validation of Syntactic Correctness of Input vulnerability in the Web-Filtering module of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an SRX device configured for UTM Web-Filtering receives a specifically malformed SSL packet, this will cause an FPC crash and restart. This issue affects Junos OS on SRX Series: * 23.2 versions from 23.2R2-S2 before 23.2R2-S5, * 23.4 versions from 23.4R2-S1 before 23.4R2-S5, * 24.2 versions before 24.2R2-S2, * 24.4 versions before 24.4R1-S3, 24.4R2. Earlier versions of Junos are also affected, but no fix is available.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Juniper | Junos | 23.2 |
| Juniper | Srx1500 | - |
| Juniper | Srx1600 | - |
| Juniper | Srx2300 | - |
| Juniper | Srx300 | - |
| Juniper | Srx320 | - |
| Juniper | Srx340 | - |
| Juniper | Srx345 | - |
| Juniper | Srx380 | - |
| Juniper | Srx4100 | - |
| Juniper | Srx4120 | - |
| Juniper | Srx4200 | - |
| Juniper | Srx4300 | - |
| Juniper | Srx4600 | - |
| Juniper | Srx4700 | - |
| Juniper | Srx5400 | - |
| Juniper | Srx5600 | - |
| Juniper | Srx5800 | - |
Related Weaknesses (CWE)
References
- https://kb.juniper.net/JSA105996Vendor Advisory
- https://supportportal.juniper.net/JSA105996Vendor Advisory
FAQ
What is CVE-2026-21917?
CVE-2026-21917 is a vulnerability with a CVSS score of 7.5 (HIGH). An Improper Validation of Syntactic Correctness of Input vulnerability in the Web-Filtering module of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause...
How severe is CVE-2026-21917?
CVE-2026-21917 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-21917?
Check the references section above for vendor advisories and patch information. Affected products include: Juniper Junos, Juniper Srx1500, Juniper Srx1600, Juniper Srx2300, Juniper Srx300.