CVE-2026-57021 Details
Description
An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an SRX Series device is configured for remote-access VPN with pre-logon compliance check, a network-based attacker sending specifically formatted requests can trigger an out of bounds write leading to an http-gk process crash. This crash leads to unavailability of all services depending on the [ system services web-management ] configuration (like J-Web, remote access VPN and firewall authentication) until the process automatically restarts. This issue affects Junos OS on SRX Series: * 23.2 versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2-S4, * 25.2 versions before 25.2R2, * 25.4 versions before 25.4R1-S1, 25.4R2.
A vulnerability allowing out-of-bounds write has been identified in the http-gatekeeper component of Juniper Networks Junos OS on SRX Series devices. This vulnerability allows an unauthenticated, network-based attacker to cause a denial-of-service condition. When the device is configured for remote-access VPN with pre-logon compliance checks, an attacker can send specially formatted requests that trigger the out-of-bounds write, causing the http-gk process to crash. This crash disrupts all services reliant on the web-management configuration, such as J-Web, remote access VPN, and firewall authentication, until the process automatically restarts.
Users can upgrade to Junos OS versions 23.2R2-S7, 23.4R2-S8, 24.2R2-S4, 24.4R2-S4, 25.2R2, 25.4R1-S1, 25.4R2, 26.2R1, or any subsequent release. Instructions for upgrading can be found on the Juniper Networks Customer Support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://supportportal.juniper.net/JSA110081 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| juniper junos | 23.2 - 23.2 r1 23.2 r1-s1 23.2 r1-s2 23.2 r2 23.2 r2-s1 23.2 r2-s2 23.2 r2-s3 23.2 r2-s4 23.2 r2-s5 23.2 r2-s6 23.4 - 23.4 r1 23.4 r1-s1 23.4 r1-s2 23.4 r2 23.4 r2-s1 23.4 r2-s2 23.4 r2-s3 23.4 r2-s4 23.4 r2-s5 23.4 r2-s6 23.4 r2-s7 24.2 - 24.2 r1 24.2 r1-s1 24.2 r1-s2 24.2 r2 24.2 r2-s1 24.2 r2-s2 24.2 r2-s3 24.4 - 24.4 r1 24.4 r1-s2 24.4 r1-s3 24.4 r2 24.4 r2-s1 24.4 r2-s2 24.4 r2-s3 25.2 - 25.2 r1 25.2 r1-s1 25.2 r1-s2 25.4 - 25.4 r1 |
CPE
Remediation
| |
| juniper srx1500 | All versions |
CPE
Remediation
| |
| juniper srx1600 | All versions |
CPE
Remediation
| |
| juniper srx2300 | All versions |
CPE
Remediation
| |
| juniper srx300 | All versions |
CPE
Remediation
| |
| juniper srx320 | All versions |
CPE
Remediation
| |
| juniper srx340 | All versions |
CPE
Remediation
| |
| juniper srx345 | All versions |
CPE
Remediation
| |
| juniper srx380 | All versions |
CPE
Remediation
| |
| juniper srx400 | All versions |
CPE
Remediation
| |
| juniper srx4100 | All versions |
CPE
Remediation
| |
| juniper srx4120 | All versions |
CPE
Remediation
| |
| juniper srx4200 | All versions |
CPE
Remediation
| |
| juniper srx4300 | All versions |
CPE
Remediation
| |
| juniper srx440 | All versions |
CPE
Remediation
| |
| juniper srx4600 | All versions |
CPE
Remediation
| |
| juniper srx4700 | All versions |
CPE
Remediation
| |
| juniper srx5400 | All versions |
CPE
Remediation
| |
| juniper srx5600 | All versions |
CPE
Remediation
| |
| juniper srx5800 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 13, 2026 | Initial Analysis | [email protected] |
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |