Description
An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

If an SRX Series device is configured for remote-access VPN with pre-logon compliance check, a network-based attacker sending specifically formatted requests can trigger an out of bounds write leading to an http-gk process crash. This crash leads to unavailability of all services depending on the [ system services web-management ] configuration (like J-Web, remote access VPN and firewall authentication) until the process automatically restarts.

This issue affects Junos OS on SRX Series:


* 23.2 versions before 23.2R2-S7,
* 23.4 versions before 23.4R2-S8,
* 24.2 versions before 24.2R2-S4,
* 24.4 versions before 24.4R2-S4,
* 25.2 versions before 25.2R2,
* 25.4 versions before 25.4R1-S1, 25.4R2.
Published: 2026-07-09
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write in the http‑gatekeeper (http‑gk) component of Junos OS causes the http‑gk process to crash. The crash disrupts all services that rely on the system services web‑management configuration—such as J‑Web, remote‑access VPN, and firewall authentication—until the process automatically restarts. The weakness is classified as a memory corruption flaw (CWE‑787) and does not provide code execution or data disclosure.

Affected Systems

Juniper Networks Junos OS on SRX Series routers is affected. The vulnerable releases include any firmware versions before 23.2R2‑S7, 23.4R2‑S8, 24.2R2‑S4, 24.4R2‑S4, 25.2R2, 25.4R1‑S1, and 25.4R2. Devices running these firmware releases and configured for remote‑access VPN with pre‑logon compliance checking can be impacted.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate impact. The EPSS score of < 1% suggests a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. A network‑based, unauthenticated attacker who can reach the device and send specially crafted requests to the‑gk process can trigger the crash. Although it causes a denial of service, it does not allow code execution or data exposure, so the risk is largely service disruption until mitigation is applied.

Generated by OpenCVE AI on July 28, 2026 at 08:39 UTC.

Remediation

Vendor Solution

The following software releases have been updated to resolve this specific issue: Junos OS: 23.2R2-S7, 23.4R2-S8, 24.2R2-S4, 24.4R2-S4, 25.2R2, 25.4R1-S1, 25.4R2, 26.2R1, and all subsequent releases.


Vendor Workaround

There are no known workarounds for this issue.


OpenCVE Recommended Actions

  • Upgrade Junos OS to a patched release—23.2R2‑S7 or later, 23.4R2‑S8 or later, 24.2R2‑S4 or later, 24.4R2‑S4 or later, 25.2R2 or later, 25.4R1‑S1 or later, 26.2R1, or newer versions.
  • No workaround exists; follow the official patch immediately to mitigate the vulnerability.
  • Schedule the upgrade during a maintenance window to minimize service interruption.
  • After applying the patch, monitor the http‑gatekeeper logs for crash events and set alerts to detect any future regressions.

Generated by OpenCVE AI on July 28, 2026 at 08:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os
Vendors & Products Juniper Networks
Juniper Networks junos Os

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an SRX Series device is configured for remote-access VPN with pre-logon compliance check, a network-based attacker sending specifically formatted requests can trigger an out of bounds write leading to an http-gk process crash. This crash leads to unavailability of all services depending on the [ system services web-management ] configuration (like J-Web, remote access VPN and firewall authentication) until the process automatically restarts. This issue affects Junos OS on SRX Series: * 23.2 versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S4, * 24.4 versions before 24.4R2-S4, * 25.2 versions before 25.2R2, * 25.4 versions before 25.4R1-S1, 25.4R2.
Title Junos OS: SRX Series: If VPN compliance-check is configured an attacker can cause http-gk process crash
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/AU:Y/R:A/RE:M'}


Subscriptions

Juniper Networks Junos Os
cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2026-07-10T14:28:45.161Z

Reserved: 2026-06-23T16:27:00.248Z

Link: CVE-2026-57021

cve-icon Vulnrichment

Updated: 2026-07-10T14:28:40.769Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:45:04Z

Weaknesses