CVE-2026-33782 is a memory leak vulnerability in the DHCP daemon (jdhcpd) of Juniper Networks Junos OS affecting MX Series devices. The flaw occurs in DHCPv6 over PPPoE or DHCPv6 over VLAN scenarios with active or bulk lease query functionality, where each subscriber logout fails to properly release allocated memory. This memory exhaustion eventually causes the jdhcpd process to crash and restart, resulting in complete service disruption. The vulnerability impacts all versions of Junos OS prior to 22.4R3-S1, all 23.2 versions before 23.2R2, and all 23.4 versions before 23.4R2. The vulnerability carries a CVSS score of 6.5 (Medium), with an attack vector of adjacent network access requiring no authentication or user interaction. The attack has low complexity, affecting only availability rather than confidentiality or integrity. An unauthenticated attacker positioned on the same network segment could trigger repeated subscriber logouts to exhaust memory and force service outages. There is currently no evidence of active exploitation or public exploit code availability. The vulnerability is not listed on the Known Exploited Vulnerabilities catalog, and the EPSS probability score of 0.00048 indicates minimal likelihood of exploitation in the wild. This represents a low-urgency remediation window, though organizations running affected Junos OS versions on MX Series platforms should apply available patches during normal maintenance cycles.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 22.4R3-S1CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 23.2, < 23.2R2CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
>= 23.4, < 23.4R2CPE match | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
< 22.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
22.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:22.4:-:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.