Description
An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).If the SIP ALG is enabled on an affected device, the processing of a malformed SIP invite packet will cause a flow processing daemon (flowd) crash and restart. This leads to a complete service outage until the system has automatically recovered.



This issue affects Junos OS on MX Series with SPC3 and SRX Series:


* all versions before 23.2R2-S7,
* 23.4 versions before 23.4R2-S8,
* 24.2 versions before 24.2R2-S5,
* 24.4 versions before 24.4R2-S4,
* 25.2 versions before 25.2R2,
* 25.4 versions before 25.4R1-S2.
Published: 2026-07-09
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper validation of SIP invite syntax in Junos OS’s SIP plugin allows an attacker to send a malformed SIP invite that causes the flowd crash triggers a restart of the flow processing system, leading to a complete denial of service until the device automatically recovers. The flaw is categorized as CWE‑1286 – Improper Validation of Syntactic Correctness of Input, and it requires no authentication or privileged access.

Affected Systems

Juniper Networks Junos OS running on MX Series with SPC3 and SRX Series in releases before 23.2R2‑S7, 23.4R2‑S8, 24.2R2‑S5, 24.4R2‑S4, 25.2R2, and 25.4R1‑S2 are vulnerable.

Risk and Exploitability

The CVSS score of 8.7 signals high severity. The EPSS score of <1% indicates a low but nonzero exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw from any network host that can reach the SIP ALG on the affected device, typically over standard SIP ports. A single malformed SIP invite will crash the flow daemon and cause a system‑wide service outage until automatic recovery occurs.

Generated by OpenCVE AI on July 26, 2026 at 14:41 UTC.

Remediation

Vendor Solution

The following software releases have been updated to resolve this specific issue: Junos OS: 23.2R2-S7, 23.4R2-S8, 24.2R2-S5, 24.4R2-S4, 25.2R2, 25.4R1-S2, 25.4R2, 26.2R1, and all subsequent releases.


Vendor Workaround

There are no known workarounds for this issue. To reduce the risk of exploitation customers not requiring the SIP ALG functionality could explicitly disable it (in case it's by default enabled) by configuring: [ security alg sip disable ]


OpenCVE Recommended Actions

  • Upgrade Junos OS to a patched release such as 23.2R2‑S7 or later, 23.4R2‑S8 or later, 24.2R2‑S5 or later, 24.4R2‑S4 or later, 25.2R2 or later, 25.4R1‑S2 or later, or 26.2R1 and subsequent releases.
  • If the SIP ALG feature is not required for your deployment, disable it by configuring security alg sip disable to eliminate the vulnerable processing path.
  • Restrict traffic to trusted networks using firewall or ACL rules so that only authorized hosts can reach the SIP ALG interface, reducing the attack surface.

Generated by OpenCVE AI on July 26, 2026 at 14:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os
Vendors & Products Juniper Networks
Juniper Networks junos Os

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).If the SIP ALG is enabled on an affected device, the processing of a malformed SIP invite packet will cause a flow processing daemon (flowd) crash and restart. This leads to a complete service outage until the system has automatically recovered. This issue affects Junos OS on MX Series with SPC3 and SRX Series: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S5, * 24.4 versions before 24.4R2-S4, * 25.2 versions before 25.2R2, * 25.4 versions before 25.4R1-S2.
Title Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP invite causes a flowd crash
Weaknesses CWE-1286
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/R:A/RE:M'}


Subscriptions

Juniper Networks Junos Os
cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2026-07-10T14:33:07.076Z

Reserved: 2026-06-23T16:27:00.248Z

Link: CVE-2026-57026

cve-icon Vulnrichment

Updated: 2026-07-10T14:33:03.249Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T14:45:07Z

Weaknesses
  • CWE-1286

    Improper Validation of Syntactic Correctness of Input