« Back to list

ES

ES Iperf3: vulnerabilities and CVEs

ES Iperf3 has 13 published vulnerabilities, 5 of them in the last 12 months. 5 are rated critical and 0 are listed by CISA as actively exploited.

CVEs13
Last 12 months5
Critical5
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-101283Critical (9.2)——Sep 30, 2026
iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated…
CVE-2026-101276Critical (9.2)——Sep 30, 2026
iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker…
CVE-2026-102253High (8.7)0.43%—Sep 29, 2026
iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the server's UDP receive worker into an unrecoverable infinite loop by sending a single…
CVE-2026-71218Medium (5.3)0.67%—Aug 11, 2026
A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without an upper bound. This…
CVE-2026-71217High (7.5)0.82%—Aug 11, 2026
A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by…
CVE-2025-54351Critical (10)0.41%—Aug 3, 2025
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
CVE-2025-54350Medium (5.3)0.42%—Aug 3, 2025
In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt.
CVE-2025-54349Critical (10)0.40%—Aug 3, 2025
In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.
CVE-2024-53580High (7.5)0.92%—Dec 18, 2024
iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
CVE-2024-26306Medium (5.9)1.1%—May 14, 2024
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover…
CVE-2023-7250Medium (5.3)0.93%—Mar 18, 2024
A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the…
CVE-2023-38403High (7.5)2.0%—Jul 17, 2023
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
CVE-2016-4303Critical (9.8)7.0%—Sep 26, 2016
The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON…