A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the JSON_read() function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the attacker to trigger excessive memory consumption, leading to a Denial of Service (DoS) through memory exhaustion, severe slowdown, or termination of the iperf3 service.
{
"cwe_ids": [
"CWE-789"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71218.json",
"cna_assigner": "redhat"
}"2026-08-13T08:06:41Z"
[
{
"id": "CVE-2026-71218-71e1a0f1",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"304270774645485955517266248989205549676",
"283325794397299007201438548004275922011",
"202655944338123134059443406346973678838",
"28143696863415599732192840274117969379",
"262599662267697990946627437144199552407"
]
},
"source": "https://github.com/esnet/iperf/commit/0128d0357b7e8916fe39e980e455729bc0e5fd4e",
"target": {
"file": "src/iperf_api.c"
}
},
{
"id": "CVE-2026-71218-77dbe087",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 632.0,
"function_hash": "171469153698128760994736031743764477921"
},
"source": "https://github.com/esnet/iperf/commit/0128d0357b7e8916fe39e980e455729bc0e5fd4e",
"target": {
"function": "JSON_read",
"file": "src/iperf_api.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71218.json"