CVE-2026-33780 is a memory leak vulnerability in Juniper Networks Junos OS and Junos OS Evolved affecting the Layer 2 Address Learning Daemon (l2ald). The flaw occurs in EVPN-MPLS environments where routes learned from remote multi-homed Provider Edge devices are not properly released from memory during route churn, causing the l2ald process to eventually crash and restart. The vulnerability affects multiple versions of both Junos OS and Junos OS Evolved, with patches available in versions 22.4R3-S5 and later across both product lines. The vulnerability has a CVSS score of 6.5 (Medium severity) with an adjacent network attack vector requiring no authentication or user interaction. While the attack complexity is low and no special privileges are needed, the impact is limited to availability disruption rather than confidentiality or integrity compromise. An adjacent unauthenticated attacker can trigger the memory leak and cause a denial of service condition through route churn in the network. There is no evidence of active exploitation, with an EPSS score of 0.0002 indicating extremely low real-world exploitability. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and has inactive status on the Hot List, suggesting minimal community attention and no publicly available exploit code. Organizations should prioritize patching based on their risk tolerance and operational requirements rather than immediate threat landscape pressure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 22.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:* | ||
22.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:22.4:-:*:*:*:*:*:* | ||
22.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:22.4:r1:*:*:*:*:*:* | ||
22.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:22.4:r1-s1:*:*:*:*:*:* | ||
22.4CPE matchmatch criteria | cpe:2.3:o:juniper:junos:22.4:r1-s2:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:M/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.