OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-101283

CRITICAL · CVSS 9.2 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A pre-authentication heap buffer overflow vulnerability in iperf3 versions 3.20 to 3.21 allows unauthenticated attackers to exploit the decrypt_rsa_message() function by sending oversized ciphertext, potentially leading to arbitrary code execution. Organizations using these versions should prioritize patching to version 3.22 to mitigate the risk of exploitation, given the critical severity rating of 9.2. Immediate action is essential for any systems relying on iperf3 for network performance testing.

CVE
CVE-2026-101283
Severity
CRITICAL
CVSS
9.2
EPSS
0.28%

Original NVD Description

iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22