PT-2026-56975 · Juniper Networks · Junos

CVE-2026-57021

·

Published

2026-07-09

·

Updated

2026-07-10

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Junos OS on SRX Series versions prior to 23.2R2-S7 Junos OS on SRX Series versions prior to 23.4R2-S8 Junos OS on SRX Series versions prior to 24.2R2-S4 Junos OS on SRX Series versions prior to 24.4R2-S4 Junos OS on SRX Series versions prior to 25.2R2 Junos OS on SRX Series versions prior to 25.4R1-S1 Junos OS on SRX Series versions prior to 25.4R2
Description An out-of-bounds write in the http-gatekeeper (http-gk) allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). This occurs when a device is configured for remote-access VPN with pre-logon compliance check. By sending specifically formatted requests, an attacker can trigger a crash of the http-gk process, resulting in the unavailability of services dependent on the system services web-management configuration, such as J-Web, remote access VPN, and firewall authentication, until the process restarts automatically.
Recommendations Update to version 23.2R2-S7 or later. Update to version 23.4R2-S8 or later. Update to version 24.2R2-S4 or later. Update to version 24.4R2-S4 or later. Update to version 25.2R2 or later. Update to version 25.4R1-S1 or later. Update to version 25.4R2 or later.

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57021

Affected Products

Junos