Improper Check for Unusual or Exceptional Conditions in Junos OS and Junos OS Evolved - CVE-2026-33801

 

Improper Check for Unusual or Exceptional Conditions in Junos OS and Junos OS Evolved - CVE-2026-33801

Published: July 8, 2026


Vulnerability identifier: #VU137132
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33801
CWE-ID: CWE-754
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper check for unusual or exceptional conditions error in the routing protocol daemon (RPD). A remote non-authenticated attacker can cause a Denial-of-Service (DoS).

Upon receipt of a specifically malformed non-inet/inet6 unicast BGP update, an RPD crash and restart is triggered, which will cause a complete service outage until routing has reconverged.

The rpd crash occurs before the update can be readvertised, so there is no downstream propagation.


Affected software

Junos OS
Junos OS Evolved

How to mitigate CVE-2026-33801

Install updates from vendor's website.

Junos OS - addressed in versions 25.2R2, 25.4R1
Junos OS Evolved - addressed in versions 25.2R2-EVO, 25.4R1-EVO

External References

Related Security Bulletins