Description
A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the attacker to trigger excessive memory consumption, leading to a Denial of Service (DoS) through memory exhaustion, severe slowdown, or termination of the iperf3 service.
Published: 2026-08-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

To mitigate this issue, restrict network access to the `iperf3` control port, ensuring it is only reachable by trusted clients. This can be achieved by configuring firewall rules to limit inbound connections to the `iperf3` service. Additionally, consider running the `iperf3` service within environments that enforce process or container memory limits to further contain potential resource exhaustion. Note that authentication alone is insufficient as the memory allocation occurs before authentication checks.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Iperf3 Project
Iperf3 Project iperf3
Vendors & Products Iperf3 Project
Iperf3 Project iperf3

Tue, 11 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 11 Aug 2026 10:45:00 +0000


Tue, 11 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the attacker to trigger excessive memory consumption, leading to a Denial of Service (DoS) through memory exhaustion, severe slowdown, or termination of the iperf3 service.
Title Iperf3: unbounded peer-controlled allocation in iperf3 json_read() allows unauthenticated remote memory exhaustion
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-789
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Iperf3 Project Iperf3
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-11T13:00:19.528Z

Reserved: 2026-08-05T08:41:54.899Z

Link: CVE-2026-71218

cve-icon Vulnrichment

Updated: 2026-08-11T13:00:14.163Z

cve-icon NVD

Status : Received

Published: 2026-08-11T09:17:14.200

Modified: 2026-08-11T14:17:14.967

Link: CVE-2026-71218

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-11T08:13:07Z

Links: CVE-2026-71218 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:19:40Z

Weaknesses