CVE-2026-101283

Status: Received

Description

iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22

Published
September 30, 2026 10:16 PM
Last Modified
September 30, 2026 10:16 PM
Source
98a01053-8a31-4f6d-9aa9-252be161adc6

Weaknesses (CWE)

CWE-122

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.