A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the attacker to trigger excessive memory consumption, leading to a Denial of Service (DoS) through memory exhaustion, severe slowdown, or termination of the iperf3 service.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-11 09:17
Updated : 2026-08-14 19:07
NVD link : CVE-2026-71218
Mitre link : CVE-2026-71218
CVE.ORG link : CVE-2026-71218
JSON object : View
Products Affected
No product.
CWE
CWE-789
Memory Allocation with Excessive Size Value
