---
id: CVE-2026-33799
title: >-
  An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper
  Networks Junos OS and Junos OS Evolved allows an authenticated network-based
  attacker sending specific valid SNMPv3 queries to trigger a memory leak
summary: >-
  An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper
  Networks Junos OS and Junos OS Evolved allows an authenticated network-based
  attacker sending specific valid SNMPv3 queries to trigger a memory leak. Over
  time, c…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-787
vendor: juniper
product: junos
affected:
  - junos < 21.2
  - junos = 21.2
  - junos = 21.4
  - junos = 22.1
  - junos = 22.2
  - junos = 22.3
  - junos = 22.4
  - junos = 23.2
  - junos = 23.4
  - junos_os_evolved < 21.2
  - junos_os_evolved = 21.2
  - junos_os_evolved = 21.4
  - junos_os_evolved = 22.1
  - junos_os_evolved = 22.2
  - junos_os_evolved = 22.3
  - junos_os_evolved = 22.4
  - junos_os_evolved = 23.2
  - junos_os_evolved = 23.4
patched:
  - junos 21.2
  - junos_os_evolved 21.2
published: '2026-07-09'
updated: '2026-07-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-33799'
references:
  - url: 'https://supportportal.juniper.net/JSA110074'
    label: sirt@juniper.net
tags:
  - nvd
epss: 0.00367
epssPercentile: 0.30577
ingestedAt: '2026-07-13T13:27:18.420Z'
---

## Overview

An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory leak. Over time, continuous receipt of these queries will result in snmpd process memory exhaustion, resulting in a process crash and restart, impacting the ability to monitor the system via SNMP.

Memory usage can be monitored using the following command:

user@device> show system processes extensive | match snmpd




This issue affects:

Junos OS:


  *  all versions before 21.2R3-S8;
  *  from 21.4 before 21.4R3-S7;
  *  from 22.1 before 22.1R3-S6;
  *  from 22.2 before 22.2R3-S4;
  *  from 22.3 before 22.3R3-S3;
  *  from 22.4 before 22.4R3-S2;
  *  from 23.2 before 23.2R2;
  *  from 23.4 before 23.4R2.



Junos OS Evolved:
  *  all versions before 21.2R3-S8-EVO;
  *  from 21.4 before 21.4R3-S7-EVO;
  *  all versions of 22.1-EVO,
  *  from 22.2 before 22.2R3-S4-EVO;
  *  from 22.3 before 22.3R3-S3-EVO;
  *  all versions of 22.4-EVO,
  *  from 23.2 before 23.2R2-EVO;
  *  from 23.4 before 23.4R2-EVO.

## Affected

- `junos < 21.2`
- `junos = 21.2`
- `junos = 21.4`
- `junos = 22.1`
- `junos = 22.2`
- `junos = 22.3`
- `junos = 22.4`
- `junos = 23.2`
- `junos = 23.4`
- `junos_os_evolved < 21.2`
- `junos_os_evolved = 21.2`
- `junos_os_evolved = 21.4`
- `junos_os_evolved = 22.1`
- `junos_os_evolved = 22.2`
- `junos_os_evolved = 22.3`
- `junos_os_evolved = 22.4`
- `junos_os_evolved = 23.2`
- `junos_os_evolved = 23.4`

## Remediation

Upgrade past the affected range:

- `junos 21.2`
- `junos_os_evolved 21.2`
