{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-21903",
        "tracking": {
            "current_release_date": "2026-06-09T14:14:33.209456Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-21903",
            "initial_release_date": "2026-01-14T18:38:49.022022Z",
            "revision_history": [
                {
                    "date": "2026-01-14T18:38:49.022022Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (7).| Vendor_assessment created."
                },
                {
                    "date": "2026-01-14T18:38:50.767927Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-01-15T11:10:36.417517Z",
                    "number": "3",
                    "summary": "Source connected.| CVE status created. (valid)| Products connected (1).| References created (27)."
                },
                {
                    "date": "2026-01-15T11:10:39.979978Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-01-15T20:38:39.739397Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (3).| References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-01-15T20:38:45.105874Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-01-15T21:26:26.149358Z",
                    "number": "7",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-01-15T21:26:27.436225Z",
                    "number": "8",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-01-15T21:39:23.390658Z",
                    "number": "9",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-01-16T01:41:50.974901Z",
                    "number": "10",
                    "summary": "Source connected.| CVE status created. (valid)"
                },
                {
                    "date": "2026-01-16T10:08:51.572619Z",
                    "number": "11",
                    "summary": "Source connected.| CVE status created. (valid)"
                },
                {
                    "date": "2026-01-16T14:36:54.429664Z",
                    "number": "12",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-01-23T20:30:55.620451Z",
                    "number": "13",
                    "summary": "Products connected (27).| Product Identifiers created (27)."
                },
                {
                    "date": "2026-01-23T20:31:02.323954Z",
                    "number": "14",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T06:46:30.045042Z",
                    "number": "15",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (27).| Product Identifiers created (27).| References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-03-20T06:46:33.106373Z",
                    "number": "16",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T10:02:36.252093Z",
                    "number": "17",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-04-11T14:11:49.030014Z",
                    "number": "18",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-04-11T14:12:15.944001Z",
                    "number": "19",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-06-09T14:11:57.977920Z",
                    "number": "20",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                }
            ],
            "status": "interim",
            "version": "20"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/os",
                                "product": {
                                    "name": "vers:unknown/os",
                                    "product_id": "CSAFPID-5019238",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:juniper:junos:os"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "JUNOS"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/22.4",
                                "product": {
                                    "name": "vers:unknown/22.4",
                                    "product_id": "CSAFPID-2177326",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:22.4:-:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/22.4-r1",
                                "product": {
                                    "name": "vers:unknown/22.4-r1",
                                    "product_id": "CSAFPID-5383899",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:22.4:r1:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/22.4-r1-s1",
                                "product": {
                                    "name": "vers:unknown/22.4-r1-s1",
                                    "product_id": "CSAFPID-5411615",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:22.4:r1-s1:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/22.4-r1-s2",
                                "product": {
                                    "name": "vers:unknown/22.4-r1-s2",
                                    "product_id": "CSAFPID-5383900",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:22.4:r1-s2:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/22.4-r2",
                                "product": {
                                    "name": "vers:unknown/22.4-r2",
                                    "product_id": "CSAFPID-5383901",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:22.4:r2:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/22.4-r2-s1",
                                "product": {
                                    "name": "vers:unknown/22.4-r2-s1",
                                    "product_id": "CSAFPID-5383902",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:22.4:r2-s1:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/22.4-r2-s2",
                                "product": {
                                    "name": "vers:unknown/22.4-r2-s2",
                                    "product_id": "CSAFPID-5383903",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:22.4:r2-s2:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/22.4-r3",
                                "product": {
                                    "name": "vers:unknown/22.4-r3",
                                    "product_id": "CSAFPID-5383904",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:22.4:r3:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/22.4-r3-s1",
                                "product": {
                                    "name": "vers:unknown/22.4-r3-s1",
                                    "product_id": "CSAFPID-5457142",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:22.4:r3-s1:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/22.4-r3-s2",
                                "product": {
                                    "name": "vers:unknown/22.4-r3-s2",
                                    "product_id": "CSAFPID-5412626",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:22.4:r3-s2:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/22.4-r3-s3",
                                "product": {
                                    "name": "vers:unknown/22.4-r3-s3",
                                    "product_id": "CSAFPID-5460953",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:22.4:r3-s3:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/22.4-r3-s4",
                                "product": {
                                    "name": "vers:unknown/22.4-r3-s4",
                                    "product_id": "CSAFPID-5460954",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:22.4:r3-s4:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/22.4-r3-s5",
                                "product": {
                                    "name": "vers:unknown/22.4-r3-s5",
                                    "product_id": "CSAFPID-5460963",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:22.4:r3-s5:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/22.4-r3-s6",
                                "product": {
                                    "name": "vers:unknown/22.4-r3-s6",
                                    "product_id": "CSAFPID-5460985",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:22.4:r3-s6:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/23.2",
                                "product": {
                                    "name": "vers:unknown/23.2",
                                    "product_id": "CSAFPID-2177324",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:23.2:-:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/23.2-r1",
                                "product": {
                                    "name": "vers:unknown/23.2-r1",
                                    "product_id": "CSAFPID-5383906",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:23.2:r1:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/23.2-r1-s1",
                                "product": {
                                    "name": "vers:unknown/23.2-r1-s1",
                                    "product_id": "CSAFPID-5383907",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:23.2:r1-s1:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/23.2-r1-s2",
                                "product": {
                                    "name": "vers:unknown/23.2-r1-s2",
                                    "product_id": "CSAFPID-5383908",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:23.2:r1-s2:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/23.2-r2",
                                "product": {
                                    "name": "vers:unknown/23.2-r2",
                                    "product_id": "CSAFPID-5412627",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:23.2:r2:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/23.2-r2-s1",
                                "product": {
                                    "name": "vers:unknown/23.2-r2-s1",
                                    "product_id": "CSAFPID-5460955",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:23.2:r2-s1:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/23.2-r2-s2",
                                "product": {
                                    "name": "vers:unknown/23.2-r2-s2",
                                    "product_id": "CSAFPID-5460956",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:23.2:r2-s2:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/23.2-r2-s3",
                                "product": {
                                    "name": "vers:unknown/23.2-r2-s3",
                                    "product_id": "CSAFPID-5460986",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:23.2:r2-s3:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/23.4",
                                "product": {
                                    "name": "vers:unknown/23.4",
                                    "product_id": "CSAFPID-2505280",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:23.4:-:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/23.4-r1",
                                "product": {
                                    "name": "vers:unknown/23.4-r1",
                                    "product_id": "CSAFPID-5383909",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:23.4:r1:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/23.4-r1-s1",
                                "product": {
                                    "name": "vers:unknown/23.4-r1-s1",
                                    "product_id": "CSAFPID-5412628",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:23.4:r1-s1:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/23.4-r1-s2",
                                "product": {
                                    "name": "vers:unknown/23.4-r1-s2",
                                    "product_id": "CSAFPID-5460957",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:23.4:r1-s2:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<22.4",
                                "product": {
                                    "name": "vers:unknown/<22.4",
                                    "product_id": "CSAFPID-5461372",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:o:juniper:junos:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "junos"
                    }
                ],
                "category": "vendor",
                "name": "Juniper"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/23.2|<23.2r2-s4",
                                "product": {
                                    "name": "vers:semver/23.2|<23.2r2-s4",
                                    "product_id": "CSAFPID-2972324"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/23.4|<23.4r2",
                                "product": {
                                    "name": "vers:semver/23.4|<23.4r2",
                                    "product_id": "CSAFPID-1287610"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/<22.4r3-s7",
                                "product": {
                                    "name": "vers:semver/<22.4r3-s7",
                                    "product_id": "CSAFPID-5020121"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Junos OS"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/22.4r3-s7",
                                "product": {
                                    "name": "vers:unknown/22.4r3-s7",
                                    "product_id": "CSAFPID-5429125"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/23.2r2-s4",
                                "product": {
                                    "name": "vers:unknown/23.2r2-s4",
                                    "product_id": "CSAFPID-5429126"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/23.4r2",
                                "product": {
                                    "name": "vers:unknown/23.4r2",
                                    "product_id": "CSAFPID-5429127"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/24.2r1",
                                "product": {
                                    "name": "vers:unknown/24.2r1",
                                    "product_id": "CSAFPID-5429128"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<23.2r2-s4",
                                "product": {
                                    "name": "vers:unknown/<23.2r2-s4",
                                    "product_id": "CSAFPID-5429123"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<23.4r2",
                                "product": {
                                    "name": "vers:unknown/<23.4r2",
                                    "product_id": "CSAFPID-5429124"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<=22.4r3-s7",
                                "product": {
                                    "name": "vers:unknown/<=22.4r3-s7",
                                    "product_id": "CSAFPID-5429122"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "OS"
                    }
                ],
                "category": "vendor",
                "name": "Juniper Networks"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-21903",
            "cwe": {
                "id": "CWE-121",
                "name": "Stack-based Buffer Overflow"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "A Stack-based Buffer Overflow vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS allows a network-based attacker, authenticated with low privileges to cause a Denial-of-Service (DoS). Subscribing to telemetry sensors at scale causes all FPC connections to drop, resulting in an FPC crash and restart. The issue was not seen when YANG packages for the specific sensors were installed.",
                    "title": "juniper - https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-OS-Subscribing-to-telemetry-sensors-at-scale-causes-all-FPCs-to-crash-CVE-2026-21903"
                },
                {
                    "category": "description",
                    "text": "A Stack-based Buffer Overflow vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS allows a network-based attacker, authenticated with low privileges to cause a Denial-of-Service (DoS).\n\n\n\nSubscribing to telemetry sensors at scale causes all FPC connections to drop, resulting in an FPC crash and restart.\nThe issue was not seen when YANG packages for the specific sensors were installed. \n\n\n\nThis issue affects Junos OS: \n\n\n\n  *  all versions before 22.4R3-S7,\n  *  23.2 version before 23.2R2-S4,\n  *  23.4 versions before 23.4R2.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-21903"
                },
                {
                    "category": "description",
                    "text": "A Stack-based Buffer Overflow vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS allows a network-based attacker, authenticated with low privileges to cause a Denial-of-Service (DoS).\n\n\n\nSubscribing to telemetry sensors at scale causes all FPC connections to drop, resulting in an FPC crash and restart.\nThe issue was not seen when YANG packages for the specific sensors were installed. \n\n\n\nThis issue affects Junos OS: \n\n\n\n  *  all versions before 22.4R3-S7,\n  *  23.2 version before 23.2R2-S4,\n  *  23.4 versions before 23.4R2.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-21903"
                },
                {
                    "category": "description",
                    "text": "A Stack-based Buffer Overflow vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS allows a network-based attacker, authenticated with low privileges to cause a Denial-of-Service (DoS).\n\n\n\nSubscribing to telemetry sensors at scale causes all FPC connections to drop, resulting in an FPC crash and restart.\nThe issue was not seen when YANG packages for the specific sensors were installed. \n\n\n\nThis issue affects Junos OS: \n\n\n\n  *  all versions before 22.4R3-S7,\n  *  23.2 version before 23.2R2-S4,\n  *  23.4 versions before 23.4R2.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-21903"
                },
                {
                    "category": "other",
                    "text": "0.00021",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "7.1",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "6.0",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "Is related to a product by vendor Juniper, Is related to (a version of) an uncommon product, Is related to an uncommon product source",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "The value of the most recent CVSS (V3) score, The CVSS vector string contains AV:N (Attack Vector: Network), There is cwe data available from source Nvd",
                    "title": "NCSC Score top decreasing factors"
                },
                {
                    "category": "details",
                    "text": "Severity: 2\n",
                    "title": "Vendor assessment"
                }
            ],
            "product_status": {
                "fixed": [
                    "CSAFPID-5429125",
                    "CSAFPID-5429126",
                    "CSAFPID-5429127",
                    "CSAFPID-5429128"
                ],
                "known_affected": [
                    "CSAFPID-5429122",
                    "CSAFPID-5429123",
                    "CSAFPID-5429124",
                    "CSAFPID-5019238",
                    "CSAFPID-1287610",
                    "CSAFPID-2972324",
                    "CSAFPID-5020121",
                    "CSAFPID-2177324",
                    "CSAFPID-2177326",
                    "CSAFPID-2505280",
                    "CSAFPID-5383899",
                    "CSAFPID-5383900",
                    "CSAFPID-5383901",
                    "CSAFPID-5383902",
                    "CSAFPID-5383903",
                    "CSAFPID-5383904",
                    "CSAFPID-5383906",
                    "CSAFPID-5383907",
                    "CSAFPID-5383908",
                    "CSAFPID-5383909",
                    "CSAFPID-5411615",
                    "CSAFPID-5412626",
                    "CSAFPID-5412627",
                    "CSAFPID-5412628",
                    "CSAFPID-5457142",
                    "CSAFPID-5460953",
                    "CSAFPID-5460954",
                    "CSAFPID-5460955",
                    "CSAFPID-5460956",
                    "CSAFPID-5460957",
                    "CSAFPID-5460963",
                    "CSAFPID-5460985",
                    "CSAFPID-5460986",
                    "CSAFPID-5461372"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - juniper",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-OS-Subscribing-to-telemetry-sensors-at-scale-causes-all-FPCs-to-crash-CVE-2026-21903"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0117.json"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-21903"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/21xxx/CVE-2026-21903.json"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21903"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-21903"
                },
                {
                    "category": "external",
                    "summary": "Source - hkcert",
                    "url": "https://www.hkcert.org/security-bulletin/juniper-junos-os-multiple-vulnerabilities_20260116"
                },
                {
                    "category": "external",
                    "summary": "Source - ncscclear",
                    "url": "https://advisories.ncsc.nl/advisory?id=NCSC-2026-0017"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-21903"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-21903"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=10000"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=20000"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0117.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0117"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/global-search/%40uri#sortCriteria=date%20descending&f-sf_primarysourcename=Knowledge&f-sf_articletype=Security%20Advisories&numberOfResults=100"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-BGP-update-with-a-set-of-specific-attributes-causes-rpd-crash-CVE-2025-60003"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-DHCP-Option-82-messages-from-clients-being-passed-unmodified-to-the-DHCP-server-CVE-2025-59960"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-Executing-a-specific-show-command-leads-to-an-rpd-crash-CVE-2025-59959"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-Optional-transitive-BGP-attribute-is-modified-before-propagation-to-peers-causing-sessions-to-flap-CVE-2025-60011"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-Receipt-of-specific-IS-IS-update-packet-causes-memory-leak-leading-to-RPD-crash-CVE-2026-21909"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-Unix-socket-used-to-control-the-jdhcpd-process-is-world-writable-CVE-2025-59961"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-Use-after-free-vulnerability-In-802-1X-authentication-daemon-can-cause-crash-of-the-dot1xd-process-CVE-2026-21908"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-OS-and-Junos-OS-Evolved-When-telemetry-collectors-are-frequently-subscribing-and-unsubscribing-to-sensors-chassisd-or-rpd-will-crash-CVE-2026-21921"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-OS-A-specifically-crafted-show-chassis-command-causes-chassisd-to-crash-CVE-2025-60007"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-OS-Evolved-A-Linux-kernel-vulnerability-in-the-HID-driver-allows-an-attacker-to-read-information-from-the-HID-Report-buffer-CVE-2024-50302"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-OS-Evolved-Flapping-management-interface-causes-MAC-learning-on-label-switched-interfaces-to-stop-CVE-2026-21911"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-OS-EX4000-A-high-volume-of-traffic-destinated-to-the-device-leads-to-a-crash-and-restart-CVE-2026-21913"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-OS-EX4k-Series-QFX5k-Series-In-an-EVPN-VXLAN-configuration-link-flaps-cause-Inter-VNI-traffic-drop-CVE-2026-21910"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-OS-MX10k-Series-show-system-firmware-CLI-command-may-lead-to-LC480-or-LC2101-line-card-reset-CVE-2026-21912"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-OS-Receipt-of-a-specifically-malformed-ICMP-packet-causes-an-FPC-restart-CVE-2026-0203"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-OS-SRX-and-MX-Series-When-TCP-packets-occur-in-a-specific-sequence-flowd-crashes-CVE-2026-21918"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-OS-SRX-Series-A-specifically-malformed-GTP-message-will-cause-an-FPC-crash-CVE-2026-21914"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-OS-SRX-Series-If-a-specific-request-is-processed-by-the-DNS-subsystem-flowd-will-crash-CVE-2026-21920"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-OS-SRX-Series-MX-Series-with-MX-SPC3-or-MS-MPC-Receipt-of-multiple-specific-SIP-messages-results-in-flow-management-process-crash-CVE-2026-21905"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-OS-SRX-Series-Specifically-malformed-SSL-packet-causes-FPC-crash-CVE-2026-21917"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-OS-SRX-Series-With-GRE-performance-acceleration-enabled-receipt-of-a-specific-ICMP-packet-causes-the-PFE-to-crash-CVE-2026-21906"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-OS-Subscribing-to-telemetry-sensors-at-scale-causes-all-FPCs-to-crash-CVE-2026-21903"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Junos-Space-TLS-SSL-server-supports-use-of-static-key-ciphers-ssl-static-key-ciphers-CVE-2026-21907"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://supportportal.juniper.net/s/article/2026-01-Security-Bulletin-Paragon-Automation-A-clickjacking-vulnerability-in-the-web-server-configuration-has-been-addressed-CVE-2025-52987"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd",
                    "url": "https://supportportal.juniper.net/JSA106022"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd",
                    "url": "https://kb.juniper.net/JSA106022"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1287610",
                        "CSAFPID-2177324",
                        "CSAFPID-2177326",
                        "CSAFPID-2505280",
                        "CSAFPID-2972324",
                        "CSAFPID-5019238",
                        "CSAFPID-5020121",
                        "CSAFPID-5383899",
                        "CSAFPID-5383900",
                        "CSAFPID-5383901",
                        "CSAFPID-5383902",
                        "CSAFPID-5383903",
                        "CSAFPID-5383904",
                        "CSAFPID-5383906",
                        "CSAFPID-5383907",
                        "CSAFPID-5383908",
                        "CSAFPID-5383909",
                        "CSAFPID-5411615",
                        "CSAFPID-5412626",
                        "CSAFPID-5412627",
                        "CSAFPID-5412628",
                        "CSAFPID-5429122",
                        "CSAFPID-5429123",
                        "CSAFPID-5429124",
                        "CSAFPID-5457142",
                        "CSAFPID-5460953",
                        "CSAFPID-5460954",
                        "CSAFPID-5460955",
                        "CSAFPID-5460956",
                        "CSAFPID-5460957",
                        "CSAFPID-5460963",
                        "CSAFPID-5460985",
                        "CSAFPID-5460986",
                        "CSAFPID-5461372"
                    ]
                }
            ],
            "title": "CVE-2026-21903"
        }
    ]
}