CVE-2026-57029CWE-820

Junos OS Evolved: QFX Series: When sFlow collector reachability changes evo-pfemand process can crash

Medium · published July 9, 2026

CVSS v4.0
6.0
EPSS
0%
Percentile
8.7
In the wild
Unconfirmed
What it is

A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS).

When the reachability of an sFlow collector changes, the corresponding next-hop entry is updated. If this update occurs simultaneously with the sFlow thread accessing the next-hop data (which is outside the attackers control), it causes the evo-pfemand process to crash, impacting all traffic forwarding until the automatic process restart has completed.

This issue affects Junos OS Evolved on QFX Series:

* all 23.2 versions,

* 23.4 versions before 23.4R2-S7-EVO,

* 24.2 versions before 24.2R2-S5-EVO,

* 24.4 versions before 24.4R2-S3-EVO,

* 25.2 versions before 25.2R2-EVO.

The record
Technical detail
CVSS v4.0
6.0 · MEDIUM
Vector
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/AU:Y/RE:M
EPSS
0.00190 · 8.7th percentile
Weakness
CWE-820 · Missing Synchronization
Published
2026-07-09T21:12Z
EPSS history
Timeline
  • 09 JUL 21:12Z
    Junos OS Evolved: QFX Series: When sFlow collector reachability changes evo-pfemand process can crash
    cvelistv5