Description
A Use of Incorrectly-Resolved Name or Reference vulnerability in the URL filtering plugin of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass web filtering and access downstream resources that should be unreachable.



If an MX Series device is configured with web filtering, and an attacker sends a request with a specifically formatted URL, this request will get forwarded despite the system being configured to block it. In turn, an attacker can access downstream resources that are expected to be unreachable.

This issue affects Junos OS on MX Series:


* all versions before 23.2R2-S7,
* 23.4 versions before 23.4R2-S8,
* 24.2 versions before 24.2R2-S5,
* 24.4 versions before 24.4R2-S4,
* 25.2 versions before 25.2R2-S1,
* 25.4 versions before 25.4R1-S2, 25.4R2.
Published: 2026-07-09
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a misuse of incorrectly‑resolved names or references in the URL filtering plugin of Junos OS on MX Series routers. A specially formatted URL that the filtering logic misinterprets allows the request to be forwarded and provides access to downstream resources that the organization expected to be blocked. This flaw permits unauthorized transmission of data and potential compromise of assets that rely on web filtering for protection.

Affected Systems

Affected systems are Juniper Networks Junos OS running on MX Series routers. All versions prior to Junos OS 23.2R2‑S7, 23.4R2‑S8, 24.2R2‑S5, 24.4R2‑S4, 25.2R2‑S1, 25.4R1‑S2, 25.4R2, or any earlier release are vulnerable. The vulnerability does not exist in later versions that include the security updates listed by Juniper.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, and the EPSS score of less than 1 % shows that exploitation is considered unlikely at present. Because the flaw requires no authentication and is exploitable from the network, an attacker with access to the MX router’s northbound interface can bypass the firewall’s web filtering to reach otherwise unreachable services. The vulnerability is not listed in the CISA KEV catalog, and no workaround is available, so remediation must rely on applying the patch or mitigating the exposure until the patch is installed.

Generated by OpenCVE AI on July 29, 2026 at 11:48 UTC.

Remediation

Vendor Solution

The following software releases have been updated to resolve this specific issue: Junos OS: 23.2R2-S7, 23.4R2-S8, 24.2R2-S5, 24.4R2-S4, 25.2R2-S1, 25.4R1-S2, 25.4R2, 26.2R1, and all subsequent releases.


Vendor Workaround

There are no known workarounds for this issue.


OpenCVE Recommended Actions

  • Upgrade the MX Series router to Junos OS 23.2R2‑S7 or any later release that contains the fix, such as 23.4R2‑S8, 24.2R2‑S5, 24.4R2‑S4, 25.2R2‑S1, 25.4R1‑S2, 25.4R2, 26.2R1, or any subsequent release.
  • Until the firmware update is applied, isolate or segment downstream services from the router to limit the potential reach of forged URLs, and restrict outbound traffic from MX routers to only necessary destinations using ACLs or firewalls.
  • Enable logging and monitoring of HTTP requests for patterns that match the specially formatted URLs described in the security advisory, and configure IDS block such traffic where possible.

Generated by OpenCVE AI on July 29, 2026 at 11:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Juniper Networks
Juniper Networks junos Os
Vendors & Products Juniper Networks
Juniper Networks junos Os

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description A Use of Incorrectly-Resolved Name or Reference vulnerability in the URL filtering plugin of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass web filtering and access downstream resources that should be unreachable. If an MX Series device is configured with web filtering, and an attacker sends a request with a specifically formatted URL, this request will get forwarded despite the system being configured to block it. In turn, an attacker can access downstream resources that are expected to be unreachable. This issue affects Junos OS on MX Series: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S5, * 24.4 versions before 24.4R2-S4, * 25.2 versions before 25.2R2-S1, * 25.4 versions before 25.4R1-S2, 25.4R2.
Title Junos OS: MX Series: Web filtering doesn't block specifically formatted URLs
Weaknesses CWE-706
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/AU:Y/RE:M'}


Subscriptions

Juniper Networks Junos Os
cve-icon MITRE

Status: PUBLISHED

Assigner: juniper

Published:

Updated: 2026-07-10T14:34:09.815Z

Reserved: 2026-06-23T16:55:07.912Z

Link: CVE-2026-57054

cve-icon Vulnrichment

Updated: 2026-07-10T14:34:05.278Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:00:12Z

Weaknesses
  • CWE-706

    Use of Incorrectly-Resolved Name or Reference