Use of Incorrectly-Resolved Name or Reference in Junos OS - CVE-2026-57054

 

Use of Incorrectly-Resolved Name or Reference in Junos OS - CVE-2026-57054

Published: July 8, 2026


Vulnerability identifier: #VU137147
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-57054
CWE-ID: CWE-706
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass web filtering and access downstream resources that should be unreachable.

The vulnerability exists due to use of incorrectly-resolved name or reference in the URL filtering plugin when processing specifically formatted URLs. A remote attacker can send a request with a specifically formatted URL to bypass web filtering and access downstream resources that should be unreachable.

Only MX Series devices configured with web filtering for specific URLs are exposed.


Affected software

Junos OS

How to mitigate CVE-2026-57054

Install security update from vendor's website.

Junos OS - addressed in versions 23.2R2-S7, 23.4R2-S8, 24.2R2-S5, 24.4R2-S4, 25.2R2-S1, 25.4R1-S2, 25.4R2, 26.2R1

External References

Related Security Bulletins