CVE-2026-33782Disclosure(juniper / junos)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A Missing Release of Memory after Effective Lifetime vulnerability in the DHCP daemon (jdhcpd) of Juniper Networks Junos OS on MX Series, allows an adjacent, unauthenticated attacker to cause a memory leak, that will eventually cause a complete Denial-of-Service (DoS). In a DHCPv6 over PPPoE, or DHCPv6 over VLAN with Active lease query or Bulk lease query scenario, every subscriber logout will leak a small amount of memory. When all available memory has been exhausted, jdhcpd will crash and restart which causes a complete service impact until the process has recovered. The memory usage of jdhcpd can be monitored with: user@host> show system processes extensive | match jdhcpd This issue affects Junos OS: * all versions before 22.4R3-S1, * 23.2 versions before 23.2R2, * 23.4 versions before 23.4R2.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-401

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • junos
  • mx10004
  • mx10008
  • mx2008

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-09); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
junosmx10004mx10008mx2008mx2010mx2020mx204mx240mx301mx304

4 versions affected across 12 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-09: 1Mentions · 2026-04-14: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-14: 104-0904-14
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-091
Disclosure1
2026-04-141
General1
Full discourse2 posts
  • CCB Alert@CCBalert
    General

    CVE-2026-33782 & CVE-2026-33783 vulnerabilities in #Juniper Junos OS could allow attackers to trigger a full #DoS. One affects unauthenticated adjacent attackers via memory leak, while the other can be exploited by low-privileged authenticated users. #Patch #Patch #Patch Urgently

    Post summary

    The tweet warns about two Juniper Junos OS CVEs that could cause a denial‑of‑service, outlining memory‑leak details and user privilege contexts, but offers no PoC, exploit code, active exploitation reports, or patch information.

    01000308
    7.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33782 A Missing Release of Memory after Effective Lifetime vulnerability in the DHCP daemon (jdhcpd) of Juniper Networks Junos OS on MX Series, allows an adjacent, unauthen… https://www.cve.org/CVERecord?id=CVE-2026-33782

    Post summary

    This entry announces CVE-2026-33782, a memory release vulnerability in Juniper's DHCP daemon, but does not provide PoC, exploit, or patch information.

    00000160
    57.0K followersView on X
CPE platform detail28 entries

28 of 28 entries

PartVendorProductVersionTarget SWTarget HW
OSjuniperjunos---
OSjuniperjunos22.4--
OSjuniperjunos22.4--
OSjuniperjunos22.4--
OSjuniperjunos22.4--
OSjuniperjunos22.4--
OSjuniperjunos22.4--
OSjuniperjunos22.4--
OSjuniperjunos22.4--
OSjuniperjunos23.2--
OSjuniperjunos23.2--
OSjuniperjunos23.2--
OSjuniperjunos23.2--
OSjuniperjunos23.4--
OSjuniperjunos23.4--
OSjuniperjunos23.4--
OSjuniperjunos23.4--
HWjunipermx10004---
HWjunipermx10008---
HWjunipermx2008---
HWjunipermx2010---
HWjunipermx2020---
HWjunipermx204---
HWjunipermx240---
HWjunipermx301---
HWjunipermx304---
HWjunipermx480---
HWjunipermx960---

Explore more