Iperf3
Esnet · 3 CVEs
CVE-2026-101283
CRITICAL
iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is B…
Sep 30, 2026
CVE-2026-101276
CRITICAL
iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server…
Sep 30, 2026
CVE-2026-102253
HIGH
iperf3 < 3.22 UDP Receive Worker Infinite Loop DoS
Sep 29, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-101283 | iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled cip… | CRITICAL | 0.28% | Sep 30, 2026 |
| CVE-2026-101276 | iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without canc… | CRITICAL | 0.40% | Sep 30, 2026 |
| CVE-2026-102253 | iperf3 < 3.22 UDP Receive Worker Infinite Loop DoS | HIGH | 0.43% | Sep 29, 2026 |
Showing 1 to 3 of 3 CVEs