Vulnerabilities
Summary — last 7 days
New vulnerabilities3,333▲ 343 vs. last week
Critical / high1,493▲ 121 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 117 vs. last week
13 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | Critical (9.2) | — | — | ES Iperf3AI | 9/30/2026 | 10/1/2026 | iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22 | |
| Awaiting Analysis | Critical (9.2) | — | — | ES Iperf3AI | 9/30/2026 | 10/1/2026 | iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a freed iperf_stream; fixed in 3.22. | |
| Awaiting Analysis | High (8.7) | 0.43% | — | ES Iperf3AI | 9/29/2026 | 9/30/2026 | iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the server's UDP receive worker into an unrecoverable infinite loop by sending a single crafted control-channel parameter message followed by one 16-byte UDP datagram. Attackers can… | |
| Awaiting Analysis | Medium (5.3) | 0.67% | — | ES Iperf3AI | 8/11/2026 | 8/14/2026 | A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the attacker to trigger excessive memory consumption, leading to a Denial of Service (DoS)… | |
| Awaiting Analysis | High (7.5) | 0.82% | — | ES Iperf3AI | 8/11/2026 | 8/31/2026 | A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to excessive stream and thread creation, as well… | |
| Analyzed | Critical (10) | 0.41% | — | ES Iperf3 | 8/3/2025 | 6/17/2026 | In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv). | |
| Modified | Medium (5.3) | 0.42% | — | ES Iperf3 | 8/3/2025 | 6/17/2026 | In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt. | |
| Modified | Critical (10) | 0.40% | — | ES Iperf3 | 8/3/2025 | 6/17/2026 | In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow. | |
| Modified | High (7.5) | 0.92% | — | ES Iperf3Netapp Ontap 9Netapp HCI Compute Node | 12/18/2024 | 6/17/2026 | iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function. | |
| Modified | Medium (5.9) | 1.1% | — | ES Iperf3Netapp Bootstrap OS | 5/14/2024 | 6/17/2026 | iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as… | |
| Modified | Medium (5.3) | 0.93% | — | ES Iperf3Redhat Enterprise LinuxRedhat Enterprise Linux FOR ARM 64Redhat Enterprise Linux FOR IBM Z Systems+1 | 3/18/2024 | 6/17/2026 | A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This… | |
| Modified | High (7.5) | 2.0% | — | ES Iperf3Debian LinuxFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility+2 | 7/17/2023 | 6/17/2026 | iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field. | |
| Modified | Critical (9.8) | 7.0% | — | ES Iperf3Novell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapOpensuse+1 | 9/26/2016 | 6/17/2026 | The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer overflow. |