What is CVE-2026-71218?
A vulnerability was found in iperf3's JSON_read() function. A remote unauthenticated attacker can exploit this flaw by triggering memory allocation without an upper bound via a peer-controlled message length, leading to excessive memory consumption and a Denial of Service. Updating affected iperf3 systems is recommended.
Azərbaycanca: iperf3-də JSON_read() funksiyasında zəiflik aşkarlanıb. Uzaqdan autentifikasiya olunmamış hücumçu, yuxarı hədd olmadan yaddaş ayıran zəiflikdən istifadə edərək həddindən artıq yaddaş istehlakına səbəb ola və nəticədə Denial of Service yarada bilər. Təsirə məruz qalan sistemlərdə iperf3-ü yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which component of iperf3 is affected by the vulnerability?
The vulnerability was found in the JSON_read() function of iperf3.
What can an attacker achieve by exploiting this flaw?
A remote unauthenticated attacker can trigger memory allocation without an upper bound via a peer-controlled message length, leading to excessive memory consumption and a Denial of Service.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.