What is CVE-2026-71217?
A vulnerability in iperf3's control channel allows a remote attacker to send crafted JSON with excessively large numeric parameters like `parallel` and `len`, leading to resource exhaustion (excessive streams and threads). Affected servers may become unstable; users are advised to apply network-level restrictions until an official patch is released.
Azərbaycanca: iperf3-ün idarəetmə kanalında aşkar edilmiş bu zəiflik uzaqdan hücumçuya xüsusi hazırlanmış JSON vasitəsilə həddindən artıq böyük ədədi parametrlər (`parallel`, `len`) göndərərək server resurslarını (axın, thread) tükənməsinə səbəb ola bilər. Təsirə məruz qalan serverlərin dayanıqlığı pozula bilər; istifadəçilərə rəsmi yamaq çıxana qədər şəbəkə səviyyəsində məhdudiyyət tətbiq etmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ1
How does CVE-2026-71217 affect an iperf3 server?
An attacker sends crafted JSON over the control channel with excessively large numeric values in parameters like `parallel` and `len`. This causes the server to create excessive streams and threads, leading to resource exhaustion and potential instability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.