---
id: CVE-2026-73469
title: >-
  When specific platforms are using Arista EOS with a loose Unicast Reverse Path
  Forwarding (uRPF) configuration, certain traffic may not be subjected to the
  intended verification drop
summary: >-
  When specific platforms are using Arista EOS with a loose Unicast Reverse Path
  Forwarding (uRPF) configuration, certain traffic may not be subjected to the
  intended verification drop. Consequently, traffic that should be dropped based
  on…
severity: medium
cvss: 5.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N'
cwe:
  - CWE-863
vendor: Arista Networks
product: EOS
affected:
  - EOS >= 4.35.0F <= 4.35.4M
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:08:50.420'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73469'
references:
  - url: >-
      https://www.arista.com/en/support/advisories-notices/security-advisory/24732-security-advisory-0176
    label: psirt@arista.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-16T13:41:28.008891Z'
ingestedAt: '2026-09-16T10:53:53.921Z'
epss: 0.00294
epssPercentile: 0.19523
---

## Overview

When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop. Consequently, traffic that should be dropped based on these routes could still be processed and forwarded by the device.

This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
