Juniper SRX/MX flowd crash from malformed TCP (CVE-2026-57023)
Juniper's 8 July 2026 security bulletin (JSA110083): an improper validation issue in the TCP proxy plugin of Junos OS on SRX Series and MX Series with SPC3 lets an unauthenticated, network-based attacker cause a complete denial of service. When TCP proxy is in use (ALGs, Advanced Anti-Malware, ICAP or UTM), a TCP packet with a specifically malformed header crashes flowd, causing a full service outage until the process restarts. CVSS 3.1 is 7.5; CVSS 4.0 is 8.7. Affected: 23.4 before 23.4R2-S7, 24.2 before 24.2R2-S4, 24.4 before 24.4R2-S3, 25.2 before 25.2R2. Not before 23.4R1. Juniper SIRT says it is not aware of malicious exploitation; the issue was seen during production usage. No workaround. This was part of Juniper's 8 July 2026 bulletin round (Canadian Centre for Cyber Security AV26-675).
- Product
- Juniper Junos OS on SRX Series and MX Series with SPC3
- Versions
- 23.4, 24.2, 24.4, 25.2 before the listed fixed releases
- CVSS
- (CVSS 3.1, Juniper SIRT); 8.7 (CVSS 4.0)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - Exploited in Australia?
- unknown
- Patch to
- 23.4R2-S7, 24.2R2-S4, 24.4R2-S3, 25.2R2, 25.4R1 or later
Primary: Juniper JSA110083 (CVE-2026-57023) · Vendor: Juniper SIRT · CVE: CVE-2026-57023 · Canadian Centre for Cyber Security AV26-675
