MEDIUM 5.3

CVE-2026-57021: Juniper Junos SRX Out-of-Bounds Write DoS Vulnerability

Juniper Networks Junos OS on SRX Series devices contain a memory handling flaw in their web management component that allows remote attackers to knock the system offline. If your SRX is configured to perform security checks before users log in to the VPN, an attacker can send specially crafted network traffic that crashes the web service, taking down VPN access, J-Web management, and firewall authentication until the service restarts on its own. No authentication or user interaction is needed to trigger this problem.

Source data · NVD / CISA · public domain

CVSS
3.1 · 5.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weaknesses (CWE)
CWE-787
Affected products
64 configuration(s)
Published / Modified
2026-07-09 / 2026-07-13

NVD description (verbatim)

An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an SRX Series device is configured for remote-access VPN with pre-logon compliance check, a network-based attacker sending specifically formatted requests can trigger an out of bounds write leading to an http-gk process crash. This crash leads to unavailability of all services depending on the [ system services web-management ] configuration (like J-Web, remote access VPN and firewall authentication) until the process automatically restarts. This issue affects Junos OS on SRX Series: * 23.2 versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2-S4, * 25.2 versions before 25.2R2, * 25.4 versions before 25.4R1-S1, 25.4R2.

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-57021 is an out-of-bounds write vulnerability (CWE-787) in the http-gatekeeper process of Juniper Junos OS running on SRX Series platforms. The vulnerability exists in the HTTP request handling logic when remote-access VPN is configured with pre-logon compliance check enabled. A network-based attacker can craft malformed HTTP requests that cause the http-gk process to write data beyond allocated buffer boundaries, resulting in process termination. The crash persists until automatic process restart, during which dependent services—including J-Web, remote VPN access, and firewall authentication—become unavailable. The vulnerability requires no authentication and can be triggered with a single or small number of network requests.

Business impact

For organizations operating SRX Series devices as VPN gateways or perimeter firewalls, this vulnerability creates a denial-of-service vector that could temporarily disable remote access infrastructure. Depending on the criticality of VPN connectivity and J-Web-based management workflows, repeated attacks could degrade operational continuity. The impact is bounded by automatic process restart, meaning full system recovery occurs without manual intervention, but service interruption during restart may affect business operations relying on continuous VPN or firewall management access. Organizations with high-availability VPN requirements should prioritize patching.

Affected systems

Juniper Junos OS on SRX Series is affected across multiple versions: 23.2 (before 23.2R2-S7), 23.4 (before 23.4R2-S8), 24.2 (before 24.2R2-S4), 24.4 (before 24.4R2-S4), 25.2 (before 25.2R2), and 25.4 (before 25.4R1-S1 and 25.4R2). The vulnerability is only exploitable when remote-access VPN with pre-logon compliance check is configured; default SRX configurations without this feature are not affected. Verify your running version and VPN configuration against Juniper's official security advisory.

Exploitability

This vulnerability has a CVSS 3.1 score of 5.3 (Medium severity) with a network attack vector and no authentication requirement. Exploitability is straightforward—an attacker on the network can send crafted requests without authentication or user interaction. The attack does not require knowledge of internal network structure or credentials. However, the vulnerability only manifests if pre-logon compliance check is enabled on a remote-access VPN configuration, which narrows the attack surface to specifically configured deployments. The impact is limited to denial-of-service (process crash), not data exfiltration or privilege escalation. No known public exploit code is available at this time, and the vulnerability is not yet tracked in CISA's Known Exploited Vulnerabilities catalog.

Remediation

Update Junos OS to a patched version: 23.2R2-S7 or later (23.2 track), 23.4R2-S8 or later (23.4 track), 24.2R2-S4 or later (24.2 track), 24.4R2-S4 or later (24.4 track), 25.2R2 or later (25.2 track), or 25.4R1-S1, 25.4R2, or later (25.4 track). If immediate patching is not feasible, consider disabling or limiting remote-access VPN pre-logon compliance check, or restricting network access to VPN gateway interfaces through firewall rules or network segmentation. Verify all patch versions against Juniper's official security bulletin.

Patch guidance

Consult Juniper Networks' official security advisory for CVE-2026-57021 to confirm the exact patch versions for your deployment. Test patches in a non-production environment first, as Junos updates may require configuration validation and potentially a reboot depending on your platform and deployment model. Plan patching during a maintenance window to account for any service restart. Organizations on extended support or legacy versions should check with Juniper for backport availability and support timelines.

Detection guidance

Monitor http-gk process restart events and service unavailability logs on SRX devices, particularly for unexpected crashes of web-management or VPN authentication services. Look for patterns of crash events correlated with unusual incoming HTTP traffic. If your environment supports NetFlow or deep packet inspection, track anomalous HTTP requests targeting the management interface. Check Juniper's advisory for any optional IDS/IPS signatures. Enable HTTP request logging on the SRX if available and review for malformed or oversized HTTP headers.

Why prioritize this

Prioritize this patch for SRX devices that serve as primary VPN gateways or critical authentication touchpoints. The vulnerability's exploitability is low-friction (no authentication needed, network-accessible) and the affected versions span recent and current Junos releases, meaning many organizations are likely vulnerable. Although the impact is bounded to temporary service disruption rather than data breach, repeated attacks could degrade availability SLAs. However, organizations without remote-access VPN configured, or those without pre-logon compliance check enabled, face minimal risk and may deprioritize patching.

Risk score, explained

The CVSS 3.1 score of 5.3 reflects the moderate risk profile: network attack vector and no authentication requirements elevate exploitability, but the impact is limited to availability (process crash with automatic restart) and does not include confidentiality or integrity compromise. The score appropriately balances the ease of triggering the vulnerability against its bounded impact. Real-world risk depends heavily on your network topology, VPN criticality, and whether pre-logon compliance check is actually enabled in your configuration.

Frequently asked questions

Do I need to patch if I don't use remote-access VPN on my SRX?

If your SRX is not configured for remote-access VPN, this vulnerability cannot be exploited. However, if you plan to enable VPN in the future, patching is advisable. Review your configuration with 'show configuration system services' to confirm VPN status.

What happens during the http-gk process crash and restart?

When the http-gk process crashes, J-Web management access, remote VPN authentication, and firewall authentication services become temporarily unavailable until the process automatically restarts (typically within seconds to minutes). No data loss occurs, but users attempting VPN or management access during the outage will experience connection failures.

Is this vulnerability on CISA's Known Exploited Vulnerabilities list?

As of the publication date, this vulnerability is not tracked in CISA's KEV catalog, indicating no confirmed active exploitation in the wild. However, the absence of KEV status does not eliminate the need to patch, especially for internet-facing VPN gateways.

Can I mitigate this without patching?

Temporary mitigations include disabling pre-logon compliance check if operationally feasible, restricting network access to the VPN gateway interfaces via upstream firewalls or network segmentation, and monitoring for http-gk process restarts. However, patching is the definitive fix and should be prioritized.

This analysis is provided for informational purposes and does not constitute professional security advice. All findings, patch versions, and affected versions referenced in this document are based on official Juniper Networks security advisories and should be verified against the authoritative vendor source before implementation. Organizations should conduct their own risk assessment based on their specific deployment configuration, network topology, and business criticality. SEC.co makes no warranty regarding the completeness or timeliness of this analysis. Always consult Juniper's official documentation and security bulletins for the most current and accurate patching guidance. Source: NVD (public-domain), retrieved 2026-08-17. Analysis generated by SEC.co (claude-haiku-4-5).