Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-21909 Details

Description

A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated attacker controlling an adjacent IS-IS neighbor to send a specific update packet causing a memory leak. Continued receipt and processing of these packets will exhaust all available memory, crashing rpd and creating a Denial of Service (DoS) condition. Memory usage can be monitored through the use of the 'show task memory detail' command. For example: user@junos> show task memory detail | match ted-infra   TED-INFRA-COOKIE           25   1072     28   1184     229 user@junos> show task memory detail | match ted-infra   TED-INFRA-COOKIE           31   1360     34   1472     307 This issue affects: Junos OS:  * from 23.2 before 23.2R2,  * from 23.4 before 23.4R1-S2, 23.4R2,  * from 24.1 before 24.1R2;  Junos OS Evolved:  * from 23.2 before 23.2R2-EVO,  * from 23.4 before 23.4R1-S2-EVO, 23.4R2-EVO,  * from 24.1 before 24.1R2-EVO. This issue does not affect Junos OS versions before 23.2R1 or Junos OS Evolved versions before 23.2R1-EVO.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-401Missing Release of Memory after Effective Lifetime[email protected]

Affected Products

ProductVersions
juniper junos
23.2 -
23.2 r1
23.2 r1-s1
23.2 r1-s2
23.4 -

CPE

  • cpe:2.3:o:juniper:junos:23.2:-:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:23.2:r1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:23.2:r1-s1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:23.2:r1-s2:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:23.4:-:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:23.4:r1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:23.4:r1-s1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:23.4:r2:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:24.1:-:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos:24.1:r1:*:*:*:*:*:*

Remediation

  • No remediation found in references.
juniper junos os evolved
23.2 -
23.2 r1
23.2 r1-s1
23.2 r1-s2
23.4 -

CPE

  • cpe:2.3:o:juniper:junos_os_evolved:23.2:-:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos_os_evolved:23.2:r1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos_os_evolved:23.2:r1-s1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos_os_evolved:23.2:r1-s2:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos_os_evolved:23.4:-:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos_os_evolved:23.4:r1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos_os_evolved:23.4:r1-s1:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos_os_evolved:23.4:r2:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos_os_evolved:24.1:-:*:*:*:*:*:*
  • cpe:2.3:o:juniper:junos_os_evolved:24.1:r1:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-21909
NVD Published Date:
Jan 15, 2026
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2026-21909 Details - Not Deferred