CVE-2026-71217
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Summary
A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as parallel and len, which are not properly validated by the server. This improper input validation can lead to excessive stream and thread creation, as well as large buffer allocations, causing resource exhaustion. Consequently, this can result in a Denial of Service (DoS) on the affected iperf3 server.
Affected Software
| Vendor | Product | Version Range | Status |
|---|
Weaknesses
- CWE-20: Improper Input Validation
Workarounds
To mitigate this issue, restrict network access to the iperf3 server to trusted clients or networks using firewall rules. If the iperf3 server functionality is not required, disable the iperf3 service.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
- https://access.redhat.com/security/cve/CVE-2026-71217
- https://bugzilla.redhat.com/show_bug.cgi?id=2460984
- https://github.com/esnet/iperf/commit/494dd377eca4689672becdf06a85158557db1586
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.