OVERVIEW CVE-2026-33781 is an improper input validation vulnerability in the packet forwarding engine of Juniper Networks Junos OS affecting EX4k and QFX5k Series devices configured as service-provider edge devices. The vulnerability is triggered when L2PT is enabled on User Network Interfaces (UNI) and VSTP is enabled on Network-to-Network Interfaces (NNI) in VXLAN configurations. When VSTP Bridge Protocol Data Units (BPDUs) are received on the UNI, the device fails to properly allocate packet buffers, resulting in a complete denial of service condition that persists until manual device restart. SEVERITY This vulnerability carries a CVSS v3.1 score of 6.5 (MEDIUM) with an adjacent network attack vector, low attack complexity, and no authentication or user interaction requirements. The impact is limited to availability, with no confidentiality or integrity implications. The attack is practical for adjacent network attackers, though the specific configuration requirements (L2PT on UNI and VSTP on NNI in VXLAN) limit the scope of affected deployments. Affected versions include Junos OS 24.4 releases before 24.4R2 and 25.2 releases before 25.2R1-S1 and 25.2R2. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities (KEV) catalog, and its Exploit Prediction Scoring System (EPSS) score of 0.0002 indicates minimal likelihood of exploitation in real-world scenarios. The overall community attention and threat level remain low, with no publicly disclosed exploit code or active surveillance reports.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 24.4, < 24.4R2CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
24.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:24.4:-:*:*:*:*:*:* | ||
24.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:24.4:r1:*:*:*:*:*:* | ||
24.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:24.4:r1-s2:*:*:*:*:*:* | ||
24.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:24.4:r1-s3:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
2026-04 Security Bulletin: Junos OS: EX Series, QFX Series: In a VXLAN scenario when specific control protocol packets are received, memory leaks and eventually no traffic is passed (CVE-2026-33781)
Apr 9, 20262026-04 Security Bulletin: Junos OS: EX Series, QFX Series: In a VXLAN scenario when specific control protocol packets are received, memory leaks and eventually no traffic is passed (CVE-2026-33781)
Apr 8, 2026