CVE-2026-33797 Details
Description
An Improper Input Validation vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker, sending a specific genuine BGP packet in an already established BGP session to reset only that session causing a Denial of Service (DoS). An attacker repeatedly sending the packet will sustain the Denial of Service (DoS).This issue affects Junos OS: * 25.2 versions before 25.2R2 This issue does not affect Junos OS versions before 25.2R1. This issue affects Junos OS Evolved: * 25.2-EVO versions before 25.2R2-EVO This issue does not affect Junos OS Evolved versions before 25.2R1-EVO. eBGP and iBGP are affected. IPv4 and IPv6 are affected.
A vulnerability allowing improper input validation has been identified in Juniper Networks Junos OS and Junos OS Evolved. This vulnerability allows an unauthenticated, adjacent attacker to send a specific genuine BGP packet in an already established BGP session, causing a reset of that session and leading to a denial-of-service condition. The issue can be sustained by repeatedly sending the packet. This vulnerability affects Junos OS versions 25.2 prior to 25.2R2, as well as Junos OS Evolved versions 25.2-EVO prior to 25.2R2-EVO. Both eBGP and iBGP are affected, with impact on IPv4 and IPv6.
Users can upgrade to Junos OS 25.2R2, 25.4R1, or any subsequent release. For Junos OS Evolved, versions 25.2R2-EVO, 25.4R1-EVO, or any subsequent release can be used.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.juniper.net/JSA107850 | [email protected] | Vendor Advisory |
| https://supportportal.juniper.net/JSA107850 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos | 25.2 - 25.2 r1 25.2 r1-s1 25.2 r1-s2 |
CPE
Remediation
| |
| juniper junos os evolved | 25.2 - 25.2 r1 25.2 r1-s1 25.2 r1-s2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2026 | CVE Modified | [email protected] |
| Apr 16, 2026 | Initial Analysis | [email protected] |
| Apr 9, 2026 | New CVE Received | [email protected] |