Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-71218

Опубликовано: 11 авг. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the JSON_read() function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the attacker to trigger excessive memory consumption, leading to a Denial of Service (DoS) through memory exhaustion, severe slowdown, or termination of the iperf3 service.

EPSS

Процентиль: 31%
0.00383
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-789

Связанные уязвимости

CVSS3: 5.3
ubuntu
20 дней назад

A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the attacker to trigger excessive memory consumption, leading to a Denial of Service (DoS) through memory exhaustion, severe slowdown, or termination of the iperf3 service.

CVSS3: 5.3
redhat
20 дней назад

A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the attacker to trigger excessive memory consumption, leading to a Denial of Service (DoS) through memory exhaustion, severe slowdown, or termination of the iperf3 service.

CVSS3: 5.3
msrc
17 дней назад

Iperf3: unbounded peer-controlled allocation in iperf3 json_read() allows unauthenticated remote memory exhaustion

CVSS3: 5.3
debian
20 дней назад

A flaw was found in iperf3. A remote unauthenticated attacker can expl ...

CVSS3: 5.3
github
20 дней назад

A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the attacker to trigger excessive memory consumption, leading to a Denial of Service (DoS) through memory exhaustion, severe slowdown, or termination of the iperf3 service.

EPSS

Процентиль: 31%
0.00383
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-789