ES
ES Iperf3: vulnerabilities and CVEs
ES Iperf3 has 13 published vulnerabilities, 5 of them in the last 12 months. 5 are rated critical and 0 are listed by CISA as actively exploited.
CVEs13
Last 12 months5
Critical5
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-101283 | Critical (9.2) | — | — | Sep 30, 2026 | iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated… |
| CVE-2026-101276 | Critical (9.2) | — | — | Sep 30, 2026 | iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker… |
| CVE-2026-102253 | High (8.7) | 0.43% | — | Sep 29, 2026 | iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the server's UDP receive worker into an unrecoverable infinite loop by sending a single… |
| CVE-2026-71218 | Medium (5.3) | 0.67% | — | Aug 11, 2026 | A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without an upper bound. This… |
| CVE-2026-71217 | High (7.5) | 0.82% | — | Aug 11, 2026 | A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by… |
| CVE-2025-54351 | Critical (10) | 0.41% | — | Aug 3, 2025 | In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv). |
| CVE-2025-54350 | Medium (5.3) | 0.42% | — | Aug 3, 2025 | In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt. |
| CVE-2025-54349 | Critical (10) | 0.40% | — | Aug 3, 2025 | In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow. |
| CVE-2024-53580 | High (7.5) | 0.92% | — | Dec 18, 2024 | iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function. |
| CVE-2024-26306 | Medium (5.9) | 1.1% | — | May 14, 2024 | iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover… |
| CVE-2023-7250 | Medium (5.3) | 0.93% | — | Mar 18, 2024 | A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the… |
| CVE-2023-38403 | High (7.5) | 2.0% | — | Jul 17, 2023 | iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field. |
| CVE-2016-4303 | Critical (9.8) | 7.0% | — | Sep 26, 2016 | The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON… |