An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker sending a specific BGP update over an established BGP session to cause a Denial-of-Service (DoS).
Upon receipt of a specifically malformed non-inet/inet6 unicast BGP update, an RPD crash and restart is triggered, which will cause a complete service outage until routing has reconverged. The rpd crash occurs before the update can be readvertised, so there is no downstream propagation.
This issue affects:
* Junos OS versions 25.2 before 25.2R2;
* Junos OS Evolved versions 25.2 before 25.2R2-EVO.
This issue doesn't affect Junos OS versions before 25.2R1 nor Junos OS Evolved versions before 25.2R1-EVO.
References
| Link | Resource |
|---|---|
| https://supportportal.juniper.net/JSA110076 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2026-07-09 21:16
Updated : 2026-07-13 20:36
NVD link : CVE-2026-33801
Mitre link : CVE-2026-33801
CVE.ORG link : CVE-2026-33801
JSON object : View
Products Affected
juniper
- junos_os_evolved
- junos
CWE
CWE-754
Improper Check for Unusual or Exceptional Conditions
