Alert Type

SRN - Software Release Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

MX104 ACX1000 ACX2000 ACX4000

Alert Description

Junos Software Service Release version 21.2R3-S10 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

NOTE: Starting on August 30th, 2024, we include PR's severity with each entry. See KB86335 [juniper.net] for the definition of PR's Severity

 

Junos Selective Update (JSU) feasible

Not applicable

Call to Action

Software Release Notification for your review. Since Junos 21.2 software has reached End-Of-Life stage for many platforms. Only Junos software for platforms having Junos 21.2 software as the "Last Support Software Version" (LSV) are being released.

This is for MX104, ACX1000s, ACX2000s, and ACX4000s platforms only.

Solution

Junos Software service Release version 21.2R3-S10 is now available.

21.2R3-S10 - List of Fixed issues

PR NumberSynopsisCategory: SRX ISSU infra related issues
1882569
Major
ISSU getting aborted due to configuration-synchronize failure on Junos SRX platforms
Product-Group=junos
Severity=Major
On Junos OS SRX platforms having chassis cluster configuration-synchronize configured, ISSU (In-Service Software Upgrade) gets aborted due to a configuration synchronization (config-sync) failure and the Redundancy Group (RG) priority is set to 0, preventing a successful failover during the ISSU process resulting in the ISSU process gets aborted causing the upgrade failure.
PR NumberSynopsisCategory: "agentd" software daemon
1791928
Critical
Junos OS and Junos OS Evolved: When telemetry collectors are frequently subscribing and unsubscribing to sensors chassisd or rpd will crash (CVE-2026-21921)
Product-Group=junos
Severity=Critical
A Use After Free vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker authenticated with low privileges to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA106021 [juniper.net] for more information.
PR NumberSynopsisCategory: BBE Autoconfigured DVLAN related issues
1853434
Major
Junos OS: MX Series: Mismatch between configured and received packet types causes memory leak in bbe-smgd (CVE-2026-33775)
Product-Group=junos
Severity=Major
A Missing Release of Memory after Effective Lifetime vulnerability in the BroadBand Edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA107821 [juniper.net] for more information.
PR NumberSynopsisCategory: Border Gateway Protocol
1766960
Minor
Junos OS and Junos OS Evolved: Junos OS and Junos OS Evolved: Receipt of a specific BGP UPDATE causes an rpd crash on devices with BGP multipath configured (CVE-2025-52964)
Product-Group=junos
Severity=Minor
A Reachable Assertion vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA100080 [juniper.net] for more information.
1849568
Minor
L3VPN routes are not advertised to peer when BGP sessions with route-target filter flaps
Product-Group=junos
Severity=Minor
On all Junos and Junos OS Evolved platforms, after Border Gateway Protocol (BGP) sessions configured with 'family route-target' flaps, delayed route deletion causes the loss of the Route Target Filter (RTF), preventing the node from advertising L3VPN (Layer 3 Virtual Private Network) and direct routes (e.g., loopbacks and interface routes) to the BGP peer, leading to VPN route loss and service disruption.
1857801
Major
Memory leak is observed when "graceful-shutdown" is configured
Product-Group=junos
Severity=Major
On all Junos and Junos Evolved platforms with Border Gateway Protocol (BGP) "graceful-shutdown" configured, memory leak is observed. This issue does not cause traffic impact.
1877288
Major
rpd crash when changes are applied to as-path with dynamic-db in use
Product-Group=junos
Severity=Major
On Junos OS platforms using as-path-groups (Autonomous System Path Group) with dynamic-db (dynamic Data base) feature enabled, rpd (Routing Protocol Daemon) may crash after as-path configuration changes.
1878812
Critical
Junos OS and Junos OS Evolved: BGP update with a set of specific attributes causes rpd crash (CVE-2025-60003)
Product-Group=junos
Severity=Critical
A Buffer Over-read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA103166 [juniper.net] for more information.
1883803
Major
Junos OS and Junos OS Evolved: Executing a specific show command leads to an rpd crash (CVE-2025-59959)
Product-Group=junos
Severity=Major
An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with low privileges to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA103148 [juniper.net] for more information.
1884492
Major
Junos OS and Junos OS Evolved: Optional transitive BGP attribute is modified before propagation to peers causing sessions to flap (CVE-2025-60011)
Product-Group=junos
Severity=Major
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause an availability impact for downstream devices. Please refer to https://supportportal.juniper.net/JSA103161 [juniper.net] for more information.
1887911
Major
The rpd process crashes after BGP configuration commits involving group-split-size and RIB-sharding
Product-Group=junos
Severity=Major
On Junos and Junos OS Evolved platforms, configuring "group-split-size" with BGP RIB-sharding(Border Gateway Protocol Routing Information Base Sharding) can lead to a crash in the routing protocol daemon (rpd) when a route update for a non-negotiated NLRI(Network Layer Reachability Information) is received in the update thread. This occurs if the NLRI is targeted at other BGP peers within the group that have negotiated it.
PR NumberSynopsisCategory: BBE Remote Access Server
1822300
Major
Junos OS and Junos OS Evolved: Vulnerability in the RADIUS protocol for Subscriber Management (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
Severity=Major
An Improper Validation of Integrity Check Value and Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in subscriber services of Juniper Networks Junos OS and Junos OS Evolved allows an on-path attacker between a RADIUS server and the RADIUS client to bypass authentication. Please refer to https://supportportal.juniper.net/JSA100056 [juniper.net] for more information.
PR NumberSynopsisCategory: MX304 Chassis specific platform
1905954
Critical
memory leak caused by using the "show ccl statistic summary ... " command
Product-Group=junos
Severity=Critical
On Junos OS and Junos OS Evolved platforms, running the command "show ccl statistic summary ... " cause memory leaks in the Packet Forwarding Engine (PFE).
PR NumberSynopsisCategory: MX Platform SW - Environment Monitoring
1854693
Minor
Junos OS: A specifically crafted 'show chassis' command causes chassisd to crash (CVE-2025-60007)
Product-Group=junos
Severity=Minor
A NULL Pointer Dereference vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS on MX, SRX and EX Series allows a local attacker with low privileges to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA103173 [juniper.net] for more information.
PR NumberSynopsisCategory: Platform PR for 1G/10G LC
1696186
Major
Junos OS: MX10k Series: 'show system firmware' CLI command may lead to LC480 or LC2101 line card reset (CVE-2026-21912)
Product-Group=junosvae
Severity=Major
A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the method to collect FPC Ethernet firmware statistics of Juniper Networks Junos OS on MX10k Series allows a local, low-privileged attacker executing the 'show system firmware' CLI command to cause an LC480 or LC2101 line card to reset. Please refer to https://supportportal.juniper.net/JSA106011 [juniper.net] for more details.
PR NumberSynopsisCategory: Firewall Filter
1872347
Major
System becomes unresponsive or crash due to frequent filter changes in a scale scenario having mib2d process in use
Product-Group=junos
Severity=Major
On Junos OS platforms, The system experiences memory exhaustion due to an mbuf (Memory Buffer) leak, system logs error message. This condition can cause the system to become unresponsive (hang state) or potentially crash, resulting in a VMcore file and service disruption. The issue arises when a firewall filter is applied to approximately 1k (1000) logical interfaces (IFLs), each filter containing over 250 terms and these filters are updated every 2-3 minutes, triggering updates for all filter attachments.
PR NumberSynopsisCategory: EVPN control plane issues
1863170
Major
Junos OS and Junos OS Evolved: In an EVPN environment, receipt of a specifically malformed BGP update causes RPD crash (CVE-2025-52949)
Product-Group=junos
Severity=Major
An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a logically adjacent BGP peer sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA100053 [juniper.net] for more information.
PR NumberSynopsisCategory: ISIS routing protocol
1847557
Critical
Link State of IS-IS IPv6 adjacency is not updated after interface flap (Due to any reason)
Product-Group=junos
Severity=Critical
On all Junos and Junos Evolved platforms with Intermediate System-to-Intermediate System (IS-IS) protocol configured with IPv6 Multitopology, in rare scenarios the IS-IS adjacency is not updated and IPv6 traffic drop is seen after restarting the FPC.
PR NumberSynopsisCategory: jdhcpd daemon
1876407
Major
Junos OS and Junos OS Evolved: DHCP Option 82 messages from clients being passed unmodified to the DHCP server (CVE-2025-59960)
Product-Group=junos
Severity=Major
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Juniper DHCP service (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved on ACX Series allows a DHCP client in one subnet to exhaust the address pools of other subnets, leading to a Denial of Service (DoS) on the downstream DHCP server. Please refer to https://supportportal.juniper.net/JSA103149 [juniper.net] for more information.
1877468
Critical
Junos OS and Junos OS Evolved: Unix socket used to control the jdhcpd process is world-writable (CVE-2025-59961)
Product-Group=junos
Severity=Critical
An Incorrect Permission Assignment for Critical Resource vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged user to write to the Unix socket used to manage the jdhcpd process, resulting in complete control over the resource. Please refer to https://supportportal.juniper.net/JSA103150 [juniper.net] for more information.
PR NumberSynopsisCategory: Adresses ALG issues found in JSF
1876029
Major
Junos OS: SRX Series, MX Series with MX-SPC3 or MS-MPC: Receipt of multiple specific SIP messages results in flow management process crash (CVE-2026-21905)
Product-Group=junos
Severity=Major
A Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the SIP application layer gateway (ALG) of Juniper Networks Junos OS on SRX Series and MX Series with MX-SPC3 or MS-MPC allows an unauthenticated network-based attacker sending specific SIP messages over TCP to crash the flow management process, leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA106004 [juniper.net] for more information.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1895790
Major
Backup node stuck in cold sync failure after FPC (Flexible PIC Concentrators) reset due to PFE crash in SRX chassis cluster
Product-Group=junos
Severity=Major
On all SRX platforms, in a chassis cluster scenario, the PFE crashes on the backup node. After the crash files are fully generated, this triggers a reset of FPC. Following the crash and FPC reset, the backup node enters a cold sync failure state and remains in that state until it is manually rebooted.
PR NumberSynopsisCategory: Firewall Network Address Translation
1897060
Major
Junos OS: SRX Series : In a NAT64 configuration, receipt of a specific, malformed ICMPv6 packet will cause the srxpfe process to crash and restart. (CVE-2026-33790)
Product-Group=junos
Severity=Major
An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX Series allows an attacker sending a specific, malformed ICMPv6 packet to cause the srxpfe process to crash and restart. Continued receipt and processing of these packets will repeatedly crash the srxpfe process and sustain the Denial of Service (DoS) condition.Please refer to https://supportportal.juniper.net/JSA107874 [juniper.net] for more information.
PR NumberSynopsisCategory: Layer2 forwarding on EX/NFX/PTX/QFX
1838335
Critical
High FPC CPU utilisation and local MAC learning failure in EVPN-MPLS scenario due to rapid MAC moves
Product-Group=junos
Severity=Critical
On all Junos platforms (except MX platforms with MPC10, MPC11, LC9600) with Ethernet Virtual Private Network (VPN) - Multiprotocol Label Switching (EVPN-MPLS) configured, Media Access Control (MAC) learning failure and high CPU utilisation in FPC is seen due to rapid MAC moves and incorrect interface state in Packet Forwarding Engine (PFE).
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1895686
Minor
License installation failure when adding license using agile licensing infra on EX4300 platforms
Product-Group=junos
Severity=Minor
On EX4300 platforms, error messages are seen and license will not be installed when license is added using agile licensing infra. The features based on this license will not be enabled when license installation fails.
PR NumberSynopsisCategory: lldp sw on MX platform
1890978
Major
Memory corruption in LLDP telemetry API when handling custom TLVs larger than 32 bytes, leads to L2cpd process crash
Product-Group=junos
Severity=Major
On all Junos and Junos OS Evolved platforms, a memory corruption vulnerability exists in the Link Layer Discovery Protocol (LLDP) telemetry API. When a Protocol Data Unit (PDU) contains custom LLDP TLV (TypeLengthValue)values exceeding 32 bytes, it can trigger a crash in the l2cpd process. This crash may lead to service impact, including traffic loss and impaired functionality of protocols such as LLDP, STP (Spanning Tree Protocol), MVRP (Multiple VLAN Registration Protocol) and ERPS (Ethernet Ring Protection Switching).
PR NumberSynopsisCategory: SW PRs for MPC10E Fabric
1892558
Major
On the MX platform with the MPC10E-10C line card, switch fabric drops are seen when there is a transition from four to three active fabric planes
Product-Group=junos
Severity=Major
On Junos MX platforms with the MPC10E-10C line card, when the switch fabric transition from four to three active fabric planes due to applying maintenance commands or automatically due to hardware faults or fabric connectivity issues, the switch fabric fails to forward traffic.
PR NumberSynopsisCategory: FreeBSD Kernel Infrastructure
1872010
Major
Junos OS: A local attacker with shell access can execute arbitrary code (CVE-2025-21590)
Product-Group=junos
Severity=Major
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. Please refer to https://supportportal.juniper.net/JSA93446 [juniper.net] for more information.
PR NumberSynopsisCategory: Periodic Packet Management Daemon
1909719
Critical
Junos and Junos OS Evolved platforms experience high CPU after FPC reboot causing unpredictable issues with protocols (OSPF/ISIS/BGP, etc.) managed by PPMD
Product-Group=junos
Severity=Critical
After upgrading or rebooting Junos/Junos OS Evolved platforms, a CPU spike may be observed in the PPMD (Periodic Packet Management Daemon) process due to repeated internal message failures. This can lead to BFD (Bidirectional Forwarding Detection) authentication failures. Additionally, other protocols that rely on authentication and PPMD for packet distribution may also be affected, potentially resulting in traffic loss.
PR NumberSynopsisCategory: PTX10K Routing Engine
1870082
Critical
Image validation fails during the Junos VM validation
Product-Group=junos
Severity=Critical
On all Junos platforms that use pkgs/junos-vmguest/mtx/vmhost-pkg-support when loading image to 25.3+, image validation fails.
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1895903
Major
Traffic loss will be observed when VPLAG is configured on Junos QFX5k and EX4k platforms
Product-Group=junos
Severity=Major
On Junos QFX5k and EX4k platforms, if VPLAG(Virtual Private Link Aggregation group) is configured and if there is event change which could make ECMP(Equal Cost Monitoring Protocol) programming to change like ECMP link flap, dcpfe restart, system reboot etc which causes traffic loss.
PR NumberSynopsisCategory: Generic platform and infra issues for MS-MIC and MS-MPC(XLP)
1899178
Critical
Service session drops are observed when CPU throttling is configured on platforms with service cards installed
Product-Group=junos
Severity=Critical
On all Junos MX platforms that have MS-MPC or MS-MIC service cards installed, the use of the CPU throttling can cause the production service sessions to be dropped.
PR NumberSynopsisCategory: SRX branch platforms
1893957
Minor
SRX configured with a native VLAN ID other than 1 experienced DHCP assignment issues and ARP resolution failures to the default gateway
Product-Group=junos
Severity=Minor
In SRX configured with a native VLAN ID other than 1, connected devices successfully obtain DHCP IP addresses but are unable to resolve ARP for the default gateway. Although the SRX sends ARP replies, these responses do not reach the connected devices. Corresponding packet discards are observed in the Packet Forwarding Engine (PFE), indicating that the ARP replies are being dropped before reaching the endpoints.
PR NumberSynopsisCategory: Stout card (MPC7) fabric issues
1880805
Critical
Fabric drops are seen on MPC10E after MX-SCBE3 is bounced
Product-Group=junos
Severity=Critical
On MX platforms with MX-SCBE3, having ingress line card as MPC2E-3D-NG/MPC3E-3D-NG/MPC3E/4E/5E/7E and egress line card as MPC10E-10C, when SCBE3 offline online happens or is done, fabric drops are observed on MPC10E-10C line card thus impacting forwarding traffic. Fabric drops are seen due to interoperability issue between these line cards.
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1897464
Critical
Memory allocation failure in all the FPCs inside the NH partition
Product-Group=junos
Severity=Critical
On all affected platforms, under rare conditions involving heavy control-plane churn and a large number of interfaces within a routing instance, memory allocation failures related to Next-Hop processing will occur. This can lead to traffic drops and, in severe cases, complete service disruption across multiple FPCs.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1865649
Major
Traffic drop from subscriber will be observed when rpf-check knob is enabled under subscriber dynamic-profile with static underlying VLAN interface
Product-Group=junos
Severity=Major
On all Junos MX platforms with BBE subscribers (Broadband Edge) over static IFLs (Logical Interface) with static underlying VLAN (Virtual Local Area Network) interface and ISSU (In-Service Software Upgrade) is performed, traffic drop will be observed when rpf-check (Reverse-path forwarding) knob is enabled under subscriber dynamic-profile.
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1864237
Critical
Observing out-of-order packets when the TCP traffic gets passed over AE bundle and tunnelled via MPLSoUDP tunnel
Product-Group=junos
Severity=Critical
On Junos OS platforms, When "dynamic tunnels" configured and "set chassis loopback-dynamic-tunnel" knob is used and when TCP (Transmission Control Protocol) traffic passed via MPLSoUDP (Multi-Protocol Label Switching Over User Datagram Protocol) tunnel through an outgoing AE (Aggregated Ethernet) bundle interface having member interfaces, use of either inner or outer header hash calculations lead to out-of-order packets at the egress. It causes service impact on related flow of traffic due to out-of-order packets.
1880860
Major
FPC crash is seen on MX series when disabling AE IFL in mixed-speed configuration without enhanced-ip enabled
Product-Group=junos
Severity=Major
On MX platforms using ukern line cards (MPC2-9, LC480, LC2101, MX10K3), disabling an AE(Aggregated Ethernet) IFL configured with mixed-speed member links and without enhanced-ip enabled causes the associated FPC to crash and reboot.
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1862890
Major
Junos OS and Junos OS Evolved: Device allows login for user with expired password (CVE-2025-60010)
Product-Group=junos
Severity=Major
A password aging vulnerability in the RADIUS client of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated, network-based attacker to access the device without enforcing the required password change. Please refer to https://supportportal.juniper.net/JSA103168 [juniper.net] for more details.
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1842247
Critical
Junos OS and Junos OS Evolved: When an unsigned Python op script configuration is present, a local low privileged user can compromise the system (CVE-2026-33793)
Product-Group=junos
Severity=Critical
An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to gain root privileges, thus compromising the system. Please refer to https://supportportal.juniper.net/JSA103142 [juniper.net] for more information.
PR NumberSynopsisCategory: Configuration management, ffp, load action
1860340
Critical
Junos OS and Junos OS Evolved: The Annotate configuration command can be used to change the configuration (CVE-2025-52989)
Product-Group=junos
Severity=Critical
An Improper Neutralization of Delimiters vulnerability in the UI of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with high privileges to modify the system configuration. Please refer to https://supportportal.juniper.net/JSA100096 [juniper.net] for more information.
PR NumberSynopsisCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1689661
Minor
The source-address on Syslog at the custom routing instance is not applied right after the reboot
Product-Group=junos
Severity=Minor
Syslog may not be sent out via configured source address when the target host exists on a custom routing-instance.
PR NumberSynopsisCategory: For GPRS security features on highend SRX series
1882028
Critical
Junos OS: SRX Series: A specifically malformed GTP message will cause an FPC crash (CVE-2026-21914)
Product-Group=junos
Severity=Critical
An Improper Locking vulnerability in the GTP plugin of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (Dos). Please refer to https://supportportal.juniper.net/JSA106015 [juniper.net] for more information.

 

List of Known Issues (Part One)

PR NumberSynopsisCategory: EX4300 Mutlicast implementation
1873129
Major
The PTP packets are dropped when IGMP snooping is enabled
Product-Group=junosvae
On EX4400, EX4100, QFX5120 and EX4650 platforms running Junos Operation System (OS), when Internet Group Management Protocol (IGMP) snooping is enabled on Virtual Extensible Local Area Network (VXLAN) Virtual Local Area Network (VLAN), all unknown multicast packets will be dropped. As a result, PTP (Precision Time Protocol) packets that use reserved multicast addresses are also discarded affecting the synchronization of the device with the clock server.

Resolved In: junos:22.4R3-S11 junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S6 junos:23.4R2-S8 junos:24.2R2-S3 junos:24.2R2-S4 junos:24.4R2 junos:24.4R2-S1 junos:25.2R2 junos:25.2R2-S1 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: EX2300/3400 PFE
1899441
Major
Traffic loss is observed on the CVLAN interfaces during the transition between SP and EP configuration style
Product-Group=junos
On Junos OS EX2300, EX3400, EX4100, EX4400, EX4650, EX4000 and QFX5K platforms with software-based MAC (Media Access Control) address learning enabled through interface-level MAC-limit or MAC-move-limit, the traffic fails to traverse CVLAN interfaces when changing the configuration mode from Service Provider (SP) style to Enterprise (EP) style and vice versa.

Resolved In: junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S3 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: NFX Layer 3 Features Software
1776216
Major
IPsec Tunnel behind NAT stops passing traffic when the NAT port Number or IP address changes
Product-Group=junos
On Junos SRX and NFX series platforms, when the peer device located behind a Network address translation (NAT) device, experiences a change in the NAT port number or Internet Protocol (IP) address, the next Dead Peer Detection (DPD) or rekey process fails to update the port number in the existing tunnel NAT Traversal (NAT-T) flow session if the DPD "always-send" is being configured. This leads to communication failure over the Internet Protocol Security (IPsec) tunnel.

Resolved In: junos:22.4R3-S2 junos:23.4R2 junos:24.1R2 junos:24.2R1 junos:24.3R1
PR NumberSynopsisCategory: NFX Series Platform Software
1858495
Major
The auto-negotiation is not working properly on NFX350 platform using 1 Gigabit Ethernet SFP
Product-Group=junos
On NFX350 platforms connected to certain peer devices over SFP 1 Gigabit Ethernet (GE) with auto-negotiation enabled at both ends, a communication issue occur during the initial connection between devices, causing a mismatch in their status. As a result, the port status on the peer device appear as up/down affecting the traffic.

Resolved In: junos:24.2R2-S2 junos:24.4R2 junos:25.2R1-S1 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: "agentd" software daemon
1688613
Major
Telemetry sensor will not stream data if using key value as wildcard '*' character for gNMI in the PFE supported sensor
Product-Group=junos
On MX platforms, when key value as wildcard '*' character for gNMI (gRPC Network Management Interface) in the PFE supported sensor is used, the telemetry sensor will not stream any data.

Resolved In: evo:22.3X80-D30-EVO evo:22.3X80-D45-EVO evo:23.1R1-EVO junos:22.4R3-S8 junos:23.1R1
PR NumberSynopsisCategory: MPC Fusion SW
1824215
Major
Incorrect speed assigned to 1G interfaces on MPC2E-3D-NG high-capacity line card modules.
Product-Group=junos
During the insertion or removal of optics on 1 Gbps interfaces attached to MPC2E-3D-NG , the interface speed may be incorrectly set to 2 bps.

Resolved In: junos:19.1R3-S15 junos:19.2R3-S12 junos:19.4R3-S16 junos:20.2R3-S11 junos:21.4R3-S12 junos:22.2R3-S7 junos:22.4R3-S8 junos:22.4R3-S9 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S1-J5 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:24.4R2-S2 junos:25.2R1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: firewall filter for australia platform
1871431
Minor
Protocols involved with TCP/IP on a lsi interface have issues as TCP 3-way handshake cannot be completed
Product-Group=junos
On all SRX platforms, when a firewall filter is attached to a logical tunnel interface or a virtual routing instance to perform selective packet mode, it causes TCP packets on lsi interface to be discarded due to the TCP 3-way handshake is not established.

Resolved In: junos:23.4R2-S4-J26 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: BBE ACI VLAN related issues
1836502
Major
The bbe-smgd process crashes when a BNG subscriber re-logs in after dvlan deletion
Product-Group=junos
On all Junos MX Series platforms, when running the Broadband Network Gateway (BNG) in IP packet-trigger mode, a client re-login while the dvlan( dynamic Virtual Local Area Network) is in a deleting state causes the bbe-smgd (Broadband Edge - Subscriber Management Daemon) daemon to crash and generate a core dump.

Resolved In: evo:24.4R1-EVO evo:25.1R1-EVO junos:22.4R3-S5-J8 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2 junos:24.4R1 junos:25.1R1
PR NumberSynopsisCategory: BBE multicast related issues
1882756
Major
The bbe-smgd process crash triggered by a multicast event failure
Product-Group=junos
On all MX platforms with Broadband Edge Subscriber Management configured, the bbe-smgd process crashes when the multicast sync service add publish fails. This crash is automatically recovered by the system without requiring manual intervention.

Resolved In: evo:25.3R1-EVO junos:25.3R1
PR NumberSynopsisCategory: Border Gateway Protocol
1756603
Major
RPD process crash is seen on high scale peering scenario where the sessions are un-configured/shutdown abruptly
Product-Group=junos
The RPD process crashes on all Junos and Junos OS Evolved platforms in a highly scaled scenario of more than 2000 BGP peers if the BGP sessions are un-configured/brought down abruptly. This leads to loss of routing information and will lead to loss of protocol traffic.

Resolved In: evo:22.3X50-EVO evo:22.3X80-D49-EVO evo:22.4R3-S1-EVO evo:23.2R2-EVO evo:23.3R1-EVO evo:23.3R2-EVO evo:23.4R1-EVO evo:24.1R1-EVO junos:20.3X75-D52 junos:22.3X60 junos:22.4R3-S5 junos:23.2R2 junos:23.3R1 junos:23.3R2 junos:23.4R1 junos:24.1R1
1818545
Major
BGP-LU Label is incorrect after convergence
Product-Group=junos
On all Junos and Junos OS Evolved platforms, traffic coming in with the BGP-LU label can drop post link-failure when BGP-LU (Border Gateway Protocol-Labeled-Unicast) with 'per-prefix-label' and IGP TI-LFA (Topology-Independent Loop-Free Alternate) is enabled.

Resolved In: evo:22.2R3-S7-EVO evo:22.3X80-D49-EVO evo:23.2R2-S3-EVO evo:24.2R2-EVO evo:24.3R1-EVO evo:24.4R1-EVO evo:25.2R2-EVO junos:21.2R3-S9 junos:21.2X35 junos:22.2R3-S6 junos:22.2R3-S7 junos:22.3R3-S5 junos:22.4R3-J1 junos:22.4R3-S10 junos:22.4R3-S4 junos:23.2R2-S3 junos:23.4R2-S1 junos:23.4R2-S8 junos:24.2R1-S2 junos:24.2R2 junos:24.3R1 junos:24.4R1 junos:24.4R2-S3 junos:24.4R2-S4 junos:24.4R2-S5 junos:25.2R1-S2 junos:25.2R2
1854194
Major
Handling cores when always-compare-med is configured in BGP path selection
Product-Group=junos
When using rib-groups, which copy inet.3 routes to inet.0 and inet6.3, configuring path-selection always-compare-med triggers a local RIB evaluation that will miss inet6.3 because inet6.3 tables are not initialized as a BGP RIB. As a result, Inet6.3 routes will not get updated.

Resolved In: evo:23.4R2-S8-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S7-J1 junos:23.4R2-S8 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
1861799
Major
The "advertise-inactive" configuration does not work as expected when "add-path multipath" is configured and negotiated with the neighbor
Product-Group=junos
On all Junos and Junos Evolved platforms with "advertise-inactive" configured under Border Gateway Protocol (BGP), inactive routes are not advertised to peers when "add-path multipath" is configured and negotiated with the neighbor.

Resolved In: evo:22.3X50-EVO evo:22.3X50-J3-EVO evo:22.3X80-D49-EVO evo:23.4R2-S8-EVO evo:25.2R1-EVO junos:20.3X75-D442 junos:20.3X75-D52 junos:20.3X75-D52-J3 junos:22.3X60 junos:23.2R2-S5 junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R1
1864676
Major
The rpd process will crash due to memory leak
Product-Group=junos
The rpd process will crash due to a memory leak when configuration using apply-groups or ephemeral database for "routing-options autonomous-system independent-domain".

Resolved In: evo:22.2R3-S7-EVO evo:24.4R2-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO junos:20.3X75-D442 junos:22.2R3-S7 junos:23.4R2-S5 junos:24.4R2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1
1877111
Major
The Aggregate-Bandwidth feature inconsistency on BGP Route Reflectors with VRF L3VPN Multipath
Product-Group=junos
On all Junos and Junos Evolved platforms, the aggregate-bandwidth feature does not function as expected with the device configured as a BGP (Border Gateway Protocol) Route Reflector (RR). This issue is observed specifically in scenarios involving BGP multipath bandwidth aggregation for routes originating from VRF (Virtual Routing and Forwarding) instances under the L3VPN (Layer 3 Virtual Private Network) address family.

Resolved In: evo:23.4X100-D40-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:23.4R2-S8 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.2R2 junos:25.3R1
1877261
Major
BGP updates missing graceful-shutdown community after quick sender knob flaps
Product-Group=junos
On all Junos and Junos Evolved platforms, when the graceful-shutdown sender knob is repeatedly deleted and subsequently re-added in quick intervals under a BGP (Border Gateway Protocol) session, the router CLI (command line interface) incorrectly indicates that the graceful-shutdown community is being advertised. However, the actual BGP update messages sent over the session do not include the graceful-shutdown community. This results in the graceful-shutdown community not being propagated to BGP peers during graceful shutdown events, which will potentially cause traffic forwarding issues.

Resolved In: evo:23.2R2-S5-EVO evo:23.4X100-D45-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R1-EVO evo:25.2X100-D20-EVO evo:25.2X100-EVO evo:25.3R1-EVO evo:26.3R1-EVO junos:23.2R2-S5 junos:24.2R2-J6 junos:24.2R2-S1-J4 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.3R1
1877332
Major
EBGP MULTIPATH is not set on ACTIVE route
Product-Group=junos
On all Junos/EVO platforms, in BGP multipath scenario, it is observed that due to a software issue, the Active route does not have all the ECMP legs. Hence only one leg is installed to forwarding.

Resolved In: evo:22.3X80-D49-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:24.4X200-D20-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:21.4R3-S12 junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S5 junos:23.4R2-S6 junos:23.4R2-S8 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S4 junos:25.2R1 junos:25.2R2 junos:25.3R1
1881717
Major
Incorrect MPLS label derivation with inactive EBGP route advertisement
Product-Group=junos
On Junos and Junos Evolved platforms, MPLS (Multiprotocol Label Switching) forwarding issues may occur when labels are assigned on a locally preferred IBGP (Interior Border Gateway Protocol) route, while an inactive EBGP (Exterior Border Gateway Protocol) route is advertised via Add-Path or advertise-external. When per-prefix-label allocation is either explicit or via SRGB (Segment Routing Global Block), this mismatch can result in incorrect label forwarding.

Resolved In: evo:22.3X80-D49-EVO evo:22.4R3-S8-EVO evo:23.2R2-S5-EVO evo:23.4R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:21.4R3-S12 junos:22.3R3-S5 junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S8 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S4 junos:25.2R1 junos:25.2R2 junos:25.3R1
1889749
Critical
BGP Prefix-SID Label collision causing RPD crash
Product-Group=junos
On all Junos and Junos OS Evolved platforms, In Segment Routing the RPD ( Routing Protocol Daemon ) crash was observed due to different prefixes were trying to use same label, when Bgp prefix SID ( Segment Identifier ) feature was configured and labels were derived using the SID index.

Resolved In: evo:23.4R2-S8-EVO evo:24.2R2-S3-EVO evo:24.2X2-EVO evo:24.4R2-S4-EVO evo:25.2R1-S1-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO evo:26.2R1-EVO junos:21.2R3-S8-J22 junos:23.2R2-S6 junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: BGP Segment Routing
1648377
Major
The rpd process crashes when BGP-LU with the prefix-sid attribute is enabled in Segment Routing scenario
Product-Group=junos
On all Junos and Junos OS Evolved platforms supporting Border Gateway Protocol Labeled Unicast (BGP-LU), if the bgp-prefix-sid attribute is enabled in a Segment Routing (SR) scenario, when two prefixes use the same prefix-sid at the same time, the rpd process will crash.

Resolved In: evo:22.1R2-EVO evo:22.2R1-EVO evo:22.3R1-EVO evo:25.4R1-EVO junos:21.2R3-S8-J22 junos:22.1R2 junos:22.2R1 junos:22.3R1
PR NumberSynopsisCategory: MX304 Routing Engine issues
1854658
Major
The chassisd process crashes when commit command is issued multiple times
Product-Group=junos
On Junos VMhost platforms, when commit command is issued 50-60 times in a minute, this leads to ssh session exhaustion and slow response which causes configuration commit delays and subsequently leads to a chassisd process crash and restart causing FPC restart.

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:23.4R2-S5 junos:24.2R2-S1 junos:24.2R2-S3 junos:24.4R1-S3-J1 junos:24.4R2 junos:24.4R2-S2 junos:25.1R1 junos:25.2R1
1857833
Major
The chassisd process crash is seen after the device reboot when chassisd stalls after configuration commit
Product-Group=junos
On all VMHost platforms, the chassisd crash can be seen, which can also lead to mastership switchover. This is mainly caused by a configuration commit (no specific configuration required) followed by a reboot.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S8 junos:22.4R3-S9 junos:23.2R2-S1-J12 junos:23.2R2-S4 junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S1 junos:24.2X1 junos:24.4R1-S3-J1 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Device Configuration Daemon
1845370
Major
Interface not added back to AE bundle with multiple changes in single commit
Product-Group=junos
On all Junos platforms when speed is changed on an interface which is part of AE bundle, interface will be removed and added with the updated speed. When some other operation such as interface disable is configured along with speed change on the interface in the same commit, then the interface is not removed and added to the bundle, it can cause other AE interfaces flap and traffic drop.

Resolved In: junos:19.2R3-S12 junos:19.3R3-S13 junos:20.2R3-S11 junos:21.4R3-S10 junos:22.2R3-J15 junos:22.2R3-S7 junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:23.2R2-S4 junos:23.4R2-S5 junos:24.2R2 junos:24.4R2 junos:24.4R2-S1 junos:24.4R2-S2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Firewall Filter
1856854
Major
MIB2D will see 100% CPU utilization due to MIB2D walk fail
Product-Group=junos
On PTX3000/PTX5000/PTX10008 /PTX10016/QFX10008 /PTX1000/PTX10002/ QFX10002 platforms, MIB2D will see 100% CPU utilization due to MIB2D walk failure.

Resolved In: evo:24.2R2-S1-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:22.4R3-S5-J3 junos:22.4R3-S7 junos:23.2R2-S6 junos:23.4R2-S5-J21 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: DNS software support.
1851909
Critical
Junos OS: SRX Series: If a specific request is processed by the DNS subsystem flowd will crash (CVE-2026-21920)
Product-Group=junos
An Unchecked Return Value vulnerability in the DNS module of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA106020 [juniper.net] for more information.

Resolved In: junos:22.4R3-S7 junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R2 junos:24.4R2-S1 junos:25.1R1 junos:25.2R2-S1 junos:25.4R2 junos:26.1DCB
PR NumberSynopsisCategory: Host path software for ACX platform
1889637
Major
DHCP clients do not come up when VRF leak and "dhcp-relay" with "no-snoop" are configured under a routing-instance
Product-Group=junos
On all Junos OS Evolved ACX7K Series platforms, when DHCP (Dynamic Host Configuration Protocol) relay mode is used within a routing-instance scenario, DHCP clients fail to come up because DHCP offer packets are being dropped.

Resolved In: evo:23.4R2-S7-EVO evo:24.2R2-S4-EVO evo:24.2R2-S5-EVO evo:24.4R2-S4-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: Layer 3 forwarding, both v4+v6
1881742
Major
Packet Loss is observed when explicit Null is disabled for BGP-LU routes in ECMP scenarios
Product-Group=junos
On Junos ACX5448 and ACX710 platforms, traffic drop is observed for the Labeled Unicast (BGP-LU) route prefixes with Equal-Cost Multipath (ECMP) forwarding path when explicit null is disabled.

Resolved In: junos:23.4R2-S2-J16 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: BGP MPLS VPN specific issues
1853294
Major
Packet loss observed across multiple traffic items using SR profiles within the L3VPN
Product-Group=junos
On ACX5448 and ACX710 platforms under L3VPN (Layer 3 Virtual Private Network) deployment using OSPF (Open Shortest Path First) or BGP (Border Gateway Protocol), when traffic is forwarded over SR (Segment Routing) profiles, packet loss is observed across multiple traffic items.

Resolved In: junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S2-J16 junos:23.4R2-S5 junos:23.4R2-S7 junos:24.2R2 junos:24.4R2 junos:24.4R2-S2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: ACX IFL, IFF creation
1764083
Major
Interface flaps leading to PFE crash due to FPC heap corruption
Product-Group=junos
Frequent interface flaps will lead to the PFE (Packet Forwarding Engine) crash. This issue is seen because two threads simultaneously access the same memory location.

Resolved In: evo:23.2R2-EVO evo:23.4R1-EVO junos:21.4R3-S6 junos:22.1R3-S5 junos:22.2R3-J11 junos:22.2R3-J9 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.4R3 junos:23.2R2 junos:23.2R2-J14 junos:23.4R1 junos:23.4R2 junos:23.4R2-S2 junos:24.1R1
PR NumberSynopsisCategory: EA chip ( MQSS SW issues )
1872743
Major
Packet loss or retransmissions observed on MX platforms using SFP-T transceivers
Product-Group=junos
On MX10004, MX10008 and MX10016 platforms with LC480 line cards, the use of Small Form-factor Pluggable Twisted-pair (SFP-T) transceiver will lead to packet loss or retransmissions on neighboring devices due to incorrect Inter-Packet Gap (IPG) handling.

Resolved In: evo:22.4R3-S8-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:21.4R3-S12 junos:22.4R3-S6-J8 junos:22.4R3-S8 junos:23.2R2-J22 junos:23.2R2-S5 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.3R1
1887864
Major
Packet loss observed with SFP-T modules on MX10K LC480 line cards due to IPG misalignment
Product-Group=junos
On Junos MX10004, MX10008, and MX10016 platforms using LC480 line cards, the use of Small Form-factor Pluggable Twisted-pair (SFP-T) copper transceivers, both Juniper and NON-JNPR (third-party), causes incorrect handling of the Inter-Packet Gap (IPG). Packets are transmitted with an IPG of 5 bytes instead of the required 8 bytes, leading to packet loss or retransmissions on connected peer devices. The issue is silent, with no logs or alarms.

Resolved In: evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:21.4R3-S12 junos:22.4R3-S6-J8 junos:22.4R3-S8 junos:23.2R2-J22 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.2R2-S3 junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: EVO Socket replication
1895827
Major
Adding a new key to authentication-key-chain causes kernel crash
Product-Group=junos
On all Junos Evolved platforms, when setting/changing the tolerance value of key-chain to max value of 4294967295 and committing and then adding a new key to a key-chain and performing a commit action will result in kernel crash. Device self-recovers after the crash. "show system core-dumps" can be used to check the core. Core name starts with vmcore*

Resolved In: evo:23.4R2-S6-EVO evo:24.2R2-S3-EVO evo:24.4R2-S1-EVO evo:25.2R2-EVO evo:25.4R1-EVO junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2-S1 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: AAA, auditd issues
1786580
Major
Username in accounting logs is getting truncated to 16 characters
Product-Group=junos
On all Junos OS Evolved platforms, if the username is more than 16 characters, username will be truncated to 16 characters in the accounting logs displayed for that user.

Resolved In: evo:22.3X80-D42-EVO evo:22.3X80-D43-EVO evo:23.2R2-S4-J2-EVO evo:23.4R2-S4-J2-EVO evo:24.1B1-EVO evo:24.1R1-EVO evo:24.2R1-EVO evo:26.2R1-EVO junos:23.2R2-S5 junos:23.4R2-S4-J26 junos:23.4R2-S4-J27 junos:23.4R2-S5-J17 junos:23.4X12 junos:23.4X13 junos:23.4X30-D30 junos:23.4X9 junos:24.1B1 junos:24.1R1 junos:24.2R1 junos:24.4R2-S3
PR NumberSynopsisCategory: EVPN control plane issues
1821582
Major
Deactivating protocol evpn in a routing-instance configured with 'vrf-target auto' leads to the rpd crash on both REs
Product-Group=junos
On all MX platforms the deactivation a routing-instance configured with 'vrf-target auto' while also configured with protocol evpn (Ethernet Virtual Private Network) leads to the rpd crash in all the REs (Routing Engine) present in the chassis

Resolved In: evo:24.4R1-EVO evo:25.1R1-EVO junos:24.2R2-S3 junos:24.4R1 junos:25.1R1
1841965
Major
RPD core-dump on 22.2R3-S4
Product-Group=junos
RPD core occurs when we have an L3 instance (instance type: VRF) and an L2 instance for EVPN (instance type: MAC-VRF) with duplicate MAC detection enabled.

Resolved In: evo:24.2R2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:24.4R2-S4 junos:25.1R1 junos:25.2R1
1846266
Major
The inet filters attached to the IRB interface will not function as expected
Product-Group=junos
On Junos QFX5k and EX4k platforms, in an Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN) scenario, inet filters applied to Integrated Routing and Bridging (IRB) interfaces will not function as expected, and the associated actions of the filter are not enforced.

Resolved In: junos:24.4R1-S1 junos:24.4R1-S3 junos:24.4R2 junos:24.4R2-S1 junos:25.1R1 junos:25.2R1 junos:25.2R1-S1
1862755
Critical
The associated EVPN RI peers are not learning routes when there is change in EVPN RI name or EVPN RI is deleted and added back
Product-Group=junos
On all Junos and Junos OS Evolved platforms with Dual RE with NSR enabled, if automatic RD (Route-Distinguisher) is used for EVPN (Ethernet VPN) RI (Routing Instances) in a scaled configuration setup, and when there is a change in the EVPN RI or the EVPN RI is deleted and added back, the associated EVPN RI remote peers are not learning routes, which results in traffic loss.

Resolved In: evo:24.2R2-S4-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: EVPN Layer-2 Forwarding
1802464
Major
VXLAN/EVPN ip-address for mac-address in forwarding table in hold state
Product-Group=junos
Once receiving the same route as Type 2 and Type 5, the address entry might be stuck in hold state once remote peer restarts. The recovery is simply to clear the mac-ip table on the remote side with 'clear ethernet-switching mac-ip-table or bounce the BGP peer. This race condition is corrected.

Resolved In: evo:22.2R3-S4-EVO evo:22.4R3-S3-EVO evo:23.4R2-EVO evo:24.2R1-EVO evo:24.2R2-EVO evo:24.3R1-EVO junos:21.4R3-S8 junos:22.2R3-S4 junos:22.4R3-S3 junos:23.4R2 junos:24.2R1 junos:24.2R2 junos:24.3R1
PR NumberSynopsisCategory: EX4400 PFE software
1866815
Major
On Junos QFX5000 series and EX4000 series platforms, an fxpc process crash triggers an FPC reboot
Product-Group=junos
On QFX5000 series and EX4000 series platforms running Junos Operating System (OS), during normal operation, the fxpc process crashes due to a routing entry continues to reference a HOLD next-hop after the associated topology neighbor has already been removed by the system causing the Flexible Physical Interface Card (PIC) Concentrator (FPC) to reboot and generate a crash file.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2 junos:24.4R2-S1 junos:24.4R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
1900891
Critical
Junos OS: EX Series, QFX Series: If the same egress filter is configured on both an IRB and a physical interface one of those is not applied (CVE-2026-33773)
Product-Group=junos
An Incorrect Initialization of Resource vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series and QFX Series device allows an unauthenticated, network-based attacker to cause an integrity impact to downstream networks.. Please refer to https://supportportal.juniper.net/JSA107815 [juniper.net] for more details.

Resolved In: junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S2 junos:24.4R2-S3 junos:25.2R2 junos:25.4R1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: EX4400 platform
1653499
Major
Additional debug logs may be printed onto device console, when device is booted from a bootable USB
Product-Group=junos
When EX4400 device is booted from a USB image with 22.1R1.8 software, additional debug log messages may be printed onto the console of the EX4400 device.

Resolved In: junos:21.1R3-S3 junos:21.1R3-S4 junos:21.2R3-S3 junos:21.3R3-S2 junos:21.3X31 junos:21.4R3 junos:22.1R1-S1 junos:22.1R2 junos:22.1R3 junos:22.1R3-S2 junos:22.2R1 junos:22.2R2 junos:22.2R3-S1 junos:22.3R1
PR NumberSynopsisCategory: PFE EVPN / VxLAN related issues on EX platforms
1847849
Critical
Junos OS: EX4k Series, QFX5k Series: In an EVPN-VXLAN configuration link flaps cause Inter-VNI traffic drop (CVE-2026-21910)
Product-Group=junos
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on EX4k Series and QFX5k Series platforms allows an unauthenticated network-adjacent attacker flapping an interface to cause traffic between VXLAN Network Identifiers (VNIs) to drop, leading to a Denial of Service (DoS). Please refer to https://supportportal.juniper.net/JSA106009 [juniper.net] for more information.

Resolved In: junos:21.2R3-S11 junos:21.4R3-S10-J4 junos:21.4R3-S12 junos:22.4R3-S8 junos:22.4R3-S9 junos:23.2R2-S5 junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2 junos:24.2R2-S3 junos:24.4R1 junos:24.4R1-S1 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: EX POE
1879702
Major
There is a PoE short circuit alarm after upgrading the device
Product-Group=junos
On all Junos EX2300, EX3400, EX4400, EX4300 platforms running in Virtual Chassis or Standalone and during normal operation of the switch when POE (Power Over Ethernet) get port status command fails to read then software reads the garbage value from the response buffer and sends to chassisd due to which it results in PoE short Circuit alarm. However, this is a non-existent PoE alarm and non-impacting issue.

Resolved In: junos:22.4R3-S8 junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Express PFE FW Features
1855459
Major
On some PTX and QFX platform parity error causes packet drop
Product-Group=junos
On Junos PTX1000, PTX5000, QFX10000, PTX10002-60C, QFX10002-60C, QFX10008, QFX10016 and PTX10000 platforms when IPv6 filter is configured that has a match condition of source/ destination address greater than 64 bits, it results in packet drops due to transient hardware parity error that occurs on the prefix table. This will only reject what is permitted, does not allow unpermitted packets unless default term is accept and is a rare issue.

Resolved In: junos:22.3X60 junos:22.4R3-S5-J3 junos:22.4R3-S6 junos:22.4X50 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Express PFE L2 fwding Features
PR NumberSynopsisCategory: Express ASIC interface
1845309
Major
Framing errors observed on the peer router when connected to PTX5K with FR optics
Product-Group=junos
On Junos PTX5K platform with QSFP56-DD-4X100G-FR, when 15xQSFP28 PIC. Physical Coding Sublayer (PCS) error observed on the peer router side FR optics when 100G FR optics used, if more number of PCS error may possibility for network impact.

Resolved In: junos:22.3X60 junos:22.3X60-J2 junos:23.2R2-S5 junos:24.2R2-S2
PR NumberSynopsisCategory: SRX4100/SRX4200 platform software
1706125
Major
ifHCOutOctets unexpected spikes in value
Product-Group=junos
On SRX4100 and SRX4200 platforms, the ifHCOutOctets interface counter values may sometimes incorrectly spike and exceed interface speed.

Resolved In: junos:20.2R3-S11 junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S6 junos:23.4R2-S5 junos:24.2R2-S3 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Libjtask for RPD tasks, scheduler, timers, memory, and slip
1861810
Major
The rpd process crash is observed while adding and removing dynamic-tunnels with scaled tunnel configuration
Product-Group=junos
On all Junos Evolved platforms, the indexing of next hop while adding and deleting dynamic tunnels causes the rpd process to crash and restart. This is a timing issue.

Resolved In: evo:22.3X80-D49-EVO evo:23.4R2-S8-EVO evo:24.2R2-S1-J8-EVO evo:24.2R2-S3-EVO evo:24.2X2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:22.4R3-S9 junos:23.2R2-S5 junos:23.4R2-S8 junos:24.2R2-S2 junos:24.2R2-S4 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Integrated Routing & Bridging (IRB) module
1871420
Major
Fragmented packets dropped in EVPN-MPLS scenario due to the IRB interface MTU limitation
Product-Group=junos
On all Junos platforms running in EVPN-MPLS (Ethernet Virtual Private Network over Multiprotocol Label Switching) scenarios, host-generated packets exceeding the IRB interface MTU (Maximum Transmission Unit) are fragmented. Only the first fragment is forwarded, while remaining fragments are dropped, leading to loss of control-plane traffic.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:20.2R3-S11 junos:22.4R3-S8 junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: ISIS routing protocol
PR NumberSynopsisCategory: jdhcpd daemon
1872292
Major
DNS resolution will fail for DNS entries written to "resolv.conf"
Product-Group=junos
On all Junos platforms with ZTP (Zero-Touch Provisioning) configuration, when the configuration is completely removed, DNS (Domain Name System) resolution for DNS entries written to "resolv.conf" will fail.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S5 junos:23.4X3 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S2 junos:25.2R1 junos:25.3R1
1885178
Major
Memory leak and DHCP process crash occur on all platforms using DHCP short-cycle protection with the client-discover-match feature
Product-Group=junos
A DHCP (Dynamic Host Configuration Protocol) process crash and memory leak can occur on Junos and Junos OS Evolved platforms acting as DHCP client or relay when the client-discover-match feature is used with both DHCP option 60 and option 82, in conjunction with DHCP short-cycle protection. Memory leak will be cleared after the device reboot due to memory exhaustion.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S4-J5 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Category for JET(JUNOS Extension Toolkit) related issues
1866016
Minor
JSD might crash when multiple clients (telemetry collectors) connecting and disconnecting.
Product-Group=junos
A race condition in the jsd process, triggered by multiple clients connecting and disconnecting simultaneously, can lead to a crash.

Resolved In: evo:22.3X80-D49-EVO evo:23.4R2-S7-EVO evo:24.2R2-S1-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:23.4R2-S6 junos:23.4R2-S7 junos:24.2R2-S1 junos:24.4R2 junos:24.4R2-S1 junos:24.4R2-S2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: jl2tpd daemon
1877876
Major
L2TP subscriber is unable to connect when configuration is loaded over default config on all Junos platforms with L2TP subscribers
Product-Group=junos
On all Junos platforms with L2TP (Layer 2 Tunneling Protocol) subscribers if source-gateway-address is not configured, new L2TP subscribers will not be able to connect when configuration is loaded over default config.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Adresses ALG issues found in JSF
1852968
Major
The SRX platform may experience a flowd process crash and generate core dump files when the ALG feature is enabled
Product-Group=junos
On SRX platforms running the Junos Operating System (OS) with Application Layer Gateway (ALG) enabled, in rare scenarios, flowd process can crash and crash files are generated. While the platform eventually recovers, traffic loss will occur during this process.

Resolved In: junos:22.4R3-S10 junos:22.4R3-S9 junos:23.2R2-S4 junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R1-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Adresses NAT/NATLIB issues found in JSF
1788400
Major
SNMP walk timeout
Product-Group=junos
On Junos MX platform with MSMPC card, NMS (Network Management System) times out when polling any data from jnxSpSvcSetIfTable OID.

Resolved In: evo:25.3R1-EVO junos:21.4R3-S5-J25 junos:22.2R3-S5 junos:22.4R3-S5 junos:23.2R2-S5 junos:24.2R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Flow Module
1854492
Major
Junos SRX platforms with chassis cluster configured experience flowd crash due to a race condition in multicast session handling
Product-Group=junos
On Junos SRX platforms with chassis cluster configured, a crash is observed in multicast scenario due to a race condition where a link flap changes the ingress interface while a session is being aged out, leading to invalid session data access. This causes the flowd process to crash, resulting in a coredump and eventually the system crashes.

Resolved In: junos:22.4R3-S7 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.2R2-S3 junos:24.4R2 junos:24.4R2-S2 junos:25.2R1 junos:25.3R1
1868005
Major
Junos OS: SRX Series: With GRE performance acceleration enabled, receipt of a specific ICMP packet causes the PFE to crash (CVE-2026-21906)
Product-Group=junos
An Improper Handling of Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated network-based attacker sending a specific ICMP packet through a GRE tunnel to cause the PFE to crash and restart. Please refer to https://supportportal.juniper.net/JSA106005 [juniper.net] for more information.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2-S1 junos:24.4R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1
1876536
Major
Configuring tunnel over tunnel can leads to traffic disruption on SRX/VSRX platforms
Product-Group=junos
On all Junos SRX/VSRX platforms when tunnel over tunnel scenario is configured, the tunnel MTU (Maximum Transfer Unit) gradually decreases below the minimum MTU. As a result, this condition can lead to a srxpfe crash and traffic drop. In scenarios where a FPC (Flexible PIC Concentrator) is present, the traffic drop will be seen over the specific FPC, and after the crash happens, the FPC is restarted. In cluster scenarios, traffic on RG (Redundancy Group) will fail over to the backup node.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S3-J13 junos:23.2R2-S3-J15 junos:23.2R2-S5 junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:25.3R1
PR NumberSynopsisCategory: SRX PFE side multicast
1854130
Major
PIM IP ESP packet fragments dropped in SRX platform
Product-Group=junos
Protocol Independent Multicast (PIM) fragmented packets using IP Protocol 50 (Encapsulating Security Payload - ESP) are dropped when traversing SRX devices operating in flow mode.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S5 junos:24.2R2-S1 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1
1877771
Major
The flowd process crash is observed on all Junos SRX platforms in multicast scenario with PIM
Product-Group=junos
On all Junos SRX platforms, the flowd process crash will be observed when device is acting as MHR (Middle Hop Router) and PIM (Protocol Independent Multicast) register packet from FHR (First Hop Router) tries to build the control/data session for the same PIM register packet.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: SRX PFE side GRE/IPIP/DS-Lite/IPSec/PIM/VXLAN tunnel
1880253
Major
Traffic drops will be observed for any traffic going over the GRE tunnel post the st0 tunnel interface flap
Product-Group=junos
On Junos OS SRX platforms with Generic Routing Encapsulation (GRE) over a Secure Interface Tunnel (st0) is configured, if the st0 interface flaps, the GRE tunnel comes up before the st0 interface(which is due to a timing issue), results in a mismatch in the hash values between session packets and the GRE tunnel, which will cause traffic drop.

Resolved In: junos:22.4R3-S8 junos:23.2R2-S3-J13 junos:23.2R2-S3-J15 junos:23.2R2-S5 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S2 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: IPSEC/IKE Key Management
1841364
Major
The kmd process crash is seen on random number generation by the third-party library API
Product-Group=junos
On Junos and Junos evolved platforms on rare circumstances when device is busy kmd process crash is seen on random number generation used for VPN negotiation by the third-party library API.

Resolved In: junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3 junos:23.2R2-S4 junos:23.4R2-S4-J26 junos:23.4R2-S5 junos:24.2R2-S5 junos:24.4R1 junos:25.1R1
1864322
Major
On rare circumstances the kmd or iked process crash will be observed on using the third-party library API
Product-Group=junos
On all Junos platforms using ipsec-key-management (daemon name kmd) or the ike-key-management (daemon name iked) service for the IPSec VPN functionality, under very rare scenarios the device can be extremely overloaded so that it cannot generate a random number required for the VPN negotiation after repeated attempts. When this occurs, the VPN negotiation daemon kmd or iked can crash. The VPN operation may or may not be temporarily impacted and will recover automatically.

Resolved In: evo:24.2R2-S4-EVO junos:21.4R3-S12 junos:22.2R3-S7 junos:23.2R2-S6 junos:23.4R2-S4-J26 junos:23.4R2-S5 junos:24.2R2-S4 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: l2 flow module
1852047
Major
Traffic drops are observed when SRX380 platform is configured in l2 transparent-bridge mode
Product-Group=junos
On Junos OS SRX380 platforms, traffic drops are observed due to the default drop ACL (Access Control List) (L2 unknown unicast packets) getting applied. The issue happens when the device is configured in L2 (Layer 2) transparent-bridge mode.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2 junos:24.4R2-S3 junos:25.1R1 junos:25.2R1
1856200
Major
PFE crash due to invalid cached next hop during reinjection on SRX5k
Product-Group=junos
On SRX5k devices, the PFE (Packet Forwarding Engine) may suddenly crash with a core dump written and force a restart against all line cards during massive interface or route changes when the system caches and reinjects an invalid next hop.

Resolved In: junos:21.4R3-S12 junos:23.2R2-S7 junos:23.4R2-S4-J26 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Firewall Policy
1847877
Major
The mgd process crash is observed during large amount of configurations
Product-Group=junos
On all SRX platforms, the Management Daemon (mgd) core is seen after a large number of configurations executed when configuring the network address book and attach it to a security policy.

Resolved In: junos:19.2R3-S12 junos:19.3R3-S13 junos:20.2R3-S11 junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S3 junos:23.4R2-S4 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:25.1R1 junos:25.2R1
1882193
Critical
On SRX platform, flowd process is generating crash files
Product-Group=junos
On Junos OS SRX platforms, a crash in the flowd process occurs when the system attempts to retrieve interface information. During this process, an invalid memory address is accessed while copying the interface memory address from the database. This issue typically arises when accessing interface details to check session status on the backup device.

Resolved In: junos:19.1R3-S15 junos:19.2R3-S12 junos:19.3R3-S13 junos:19.4R3-S16 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
1894033
Critical
SRX5K traffic disruption due to REPFE policy sync issues from FQDN and file-serialization Errors
Product-Group=junos
On SRX5K series devices with file-serialization enabled, frequent policy synchronization issues occur between the Routing Engine (RE) and Packet Forwarding Engine (PFE) . This can result in traffic matching the incorrect default deny policy instead of matching the expected user-defined security policy. The issue is triggered during commit or request security policies check/resync operations, particularly when Fully Qualified Domain Name(FQDN)-based address objects are involved and have short Domain Name System Time to Live(DNS TTLs).

Resolved In: junos:24.4R2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: IPSEC/IKE VPN
1833072
Major
On rare circumstances the kmd/iked process crash will be observed on using the third-party library API
Product-Group=junos
On all Junos and Junos Evolved Platforms on rare circumstances, when the device is busy, the random number used for VPN negotiation cannot be generated by the third-party library API leading to IKEd process crash.

Resolved In: junos:21.4R3-S12 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3 junos:23.4R2-S4 junos:24.2R2-S4 junos:24.4R1 junos:25.1R1
1890872
Major
Packets are post-fragmented with DF=0
Product-Group=junos
On all SRX platforms, due to PMTU wrong calculation packets are post-fragmented, even when DF=0 is configured. This adds processing overhead and can cause downstream forwarding issues.

Resolved In: junos:23.2R2-S5 junos:23.4R2-S8 junos:24.2R2-S3 junos:24.4R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Key Management Daemon
1869769
Major
The kmd process crashes when device with MS-MPC has DPD enabled and a SA is deleted
Product-Group=junos
On all MX platforms with MS-MPC (Multiservices Modular PIC Concentrator), when DPD (Dead Peer Detection) is enabled under IPsec/IKE (Internet Key Exchange) VPN settings and for any reason an IPsec SA (Security Association) is deleted, the kmd process crashes. Due to the kmd process restart some disruption in tunnel establishment is seen.

Resolved In: junos:22.4R3-S7
1909025
Critical
Junos OS: SRX Series, MX Series: When a specifically malformed first ISAKMP packet is received, kmd/iked crashes (CVE-2026-33778)
Product-Group=junos
An Improper Validation of Syntactic Correctness of Input vulnerability in the IPsec library used by kmd and iked of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated, network-based attacker to cause a complete Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA107868 [juniper.net] for more information.

Resolved In: evo:23.4R2-S7-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:25.4R2-EVO evo:26.1R1-EVO junos:19.1R3-S15 junos:19.2R3-S12 junos:19.3R3-S13 junos:20.3X75-D52 junos:21.2R3-S11 junos:21.2X33 junos:22.3X60 junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:25.4R2 junos:26.1R1
PR NumberSynopsisCategory: Layer 2 Circuit issues
1863228
Major
IFL configured on the LAG interface goes down when the VLAN operation is changed
Product-Group=junos
On all Junos OS and Junos OS Evolved platforms, when EVPN is configured with the 'df-election-granularity per-esi' feature, any change in VLAN operation causes the IFL (logical interface) configured on the LAG (Link Aggregation Group) interface to go down, impacting all services associated with that interface.

Resolved In: evo:24.2R2-S3-EVO evo:24.4R1-S3-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.2R2-S1-J15 junos:24.2R2-S3 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: lacp protocol
1874126
Major
AE member not able to discover lost LACP peer connection leading to traffic black-holing
Product-Group=junos
On all Junos and Junos Evolved platforms, when a loop occurs in the transmission switch, the device starts receiving looped LACP (Link Aggregation Control Protocol) PDU's from itself, instead of messages from the actual peer device. This causes the system to mistakenly believe that a valid LACP connection exists, even though the peer device is not actually connected.As a result, it continues to forward traffic as if the peer were active. Since no valid peer connection is present, this can lead to traffic blackholing .

Resolved In: evo:23.2R2-S4-EVO evo:23.4R2-S3-J14-EVO evo:23.4R2-S4-J2-EVO evo:23.4R2-S4-J31-EVO evo:23.4R2-S5-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:20.3X75-D52 junos:22.3X60 junos:22.4R3-S7 junos:22.4R3-S8 junos:23.2R2-S4 junos:23.4R2-S4-J26 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.3R1 junos:25.4R1-S2 junos:25.4R2 junos:26.1R1 junos:26.2R1
PR NumberSynopsisCategory: Issues related to Junos licensing infrastructure
1872082
Critical
Junos OS and Junos OS Evolved: Execution of crafted CLI commands allows for arbitrary shell injection as root (CVE-2026-33791)
Product-Group=junos
An OS Command Injection vulnerability in the CLI processing of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker executing specific, crafted CLI commands to inject arbitrary shell commands as root, leading to a complete compromise of the system. Please refer to https://supportportal.juniper.net/JSA107875 [juniper.net] for more information.

Resolved In: evo:22.4R3-S8-EVO evo:23.2R2-S4-J2-EVO evo:23.2R2-S5-EVO evo:23.4R2-S4-J2-EVO evo:23.4R2-S6-EVO evo:23.4R2-S7-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-S1-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:21.4R3-S10-J4 junos:21.4R3-S10-J6 junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:22.4X50 junos:23.2R2-S3-J20 junos:23.2R2-S5 junos:23.4R2-S4-J26 junos:23.4R2-S4-J27 junos:23.4R2-S5-J17 junos:23.4R2-S7 junos:24.2R2-S1-J18 junos:24.2R2-S2 junos:24.2X1 junos:24.4R2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: SW PRs for MPC10E Interfaces
1727066
Major
Extremely fast interface flaps in MPC10E line-card causes cpu to hog which leads to fpc reboot.
Product-Group=junos
Extremely fast interface flaps in MPC10E line-card causes cpu to hog which leads to fpc reboot.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R1-S3 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Multiprotocol Label Switching
1793982
Major
Junos OS and Junos OS Evolved: Receipt of specific IS-IS update packet causes memory leak leading to RPD crash (CVE-2026-21909)
Product-Group=junos
A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated attacker controlling an adjacent IS-IS neighbor to send a specific update packet causing a memory leak. Continued receipt and processing of these packets will exhaust all available memory, crashing rpd and creating a Denial of Service (DoS) condition. Please refer to https://supportportal.juniper.net/JSA106008 [juniper.net] for more information.

Resolved In: evo:23.2R2-EVO evo:23.4R1-S1-J5-EVO evo:23.4R1-S1-J7-EVO evo:23.4R1-S2-EVO evo:23.4R2-EVO evo:24.1R2-EVO evo:24.2R1-EVO evo:24.3R1-EVO junos:23.2R2 junos:23.2R2-J14 junos:23.4R1-S2 junos:23.4R2 junos:24.1R2 junos:24.2R1 junos:24.3R1
1854623
Major
The rpd process crashes due to memory exhaustion
Product-Group=junos
On all Junos and Junos Evolved platforms, an out-of-memory condition in the rpd process caused by uncontrolled memory allocation leads to the rpd process crashing.

Resolved In: evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO junos:22.3X60 junos:23.4R2-S4-J9 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1
1859219
Major
RSVP-TE LSP path is not re-optimised to the path with best IGP metric
Product-Group=junos
On all Junos and Junos Evolved platforms, when RSVP-TE (Resource Reservation Protocol - Traffic Engineering) is configured with MBB (make-before-break) setup, if the protected link of the primary LSP (Label Switched Path) goes down and if "clear mpls lsp" or "clear rsvp session" commands are executed, then LSP switches to new instance from the old which will be on higher IGP (Interior Gateway Protocol) metric. However, after re-optimization, LSP will not get switched to better IGP metric path and remain in old instance. Traffic drop can be seen due to this double fault events.

Resolved In: evo:22.3X50-EVO evo:23.2R2-S4-J2-EVO evo:23.2R2-S5-EVO evo:23.4R2-S6-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.2R3-J10 junos:22.4R3-S7-J1 junos:23.2R2-S5 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R1-S2 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
1889546
Major
MPLS ping/trace not working for direct peers via routing-instance over MPLS protocols
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when a routing instance is configured at the destination device, an echo request packet is received over this routing instance interface. This routing instance should have a valid route to reach the source device. But the default routing instance should not have a valid route to reach the source device. This issue is not specific to MPLS ping over SR alone. This issue is applicable for all the protocols MPLS ping.

Resolved In: evo:24.2R2-S5-EVO evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:23.4R2-S7 junos:23.4R2-S8 junos:24.2R2-S2 junos:24.2R2-S5 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: MQTT protocol, Mosquitto Broker and Client API
1865403
Major
Memory leak is observed when Telemetry is configured
Product-Group=junos
On all Junos and Junos Evolved platforms having Telemetry configured, the memory allocations in 512 bytes slab that are seen to be growing in problem state, are related to write on a unix domain socket (internal to application). Since the data is not read, the send buffer keeps growing and the associated memory does not gets released. Every telemetry response from the producer does a 1 byte write on this socket and over a period of time the send buffer gets full. The default size of the unix socket send buffer is set to 512MB. But there is no functional impact.

Resolved In: evo:22.3X50-EVO evo:22.3X50-J3-EVO evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:23.2R2-S5-EVO evo:23.4R2-S4-J31-EVO evo:23.4R2-S5-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R1-EVO evo:25.3R1-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:21.4R3-S12 junos:22.4R3-S8 junos:22.4X8 junos:23.2R2-S5 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.2X1 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Multicast Routing
1863470
Major
The rpd crash due to memory corruption in PIM/MSDP network
Product-Group=junos
On all Junos and Junos Evolved platforms, enabling PIM (Protocol Independent Multicast) or MSDP (Multicast Source Discovery Protocol) may cause a rare memory corruption during the update of the MSDP Source Active route. This issue primarily affects highly scaled environments, leading to rpd (routing protocol daemon) coredumps and potential traffic loss.

Resolved In: evo:22.4R3-S8-EVO evo:23.2R2-S2-J10-EVO evo:23.2R2-S4-EVO evo:23.4R2-S6-EVO evo:24.2R2-S1-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:19.1R3-S15 junos:19.2R3-S12 junos:19.3R3-S13 junos:20.2R3-S11 junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S4 junos:23.4R2-S6 junos:24.2R2-S1 junos:24.4R2 junos:25.2R1 junos:25.3R1

 

Extended Solution

21.2R3-S10 - List of Known Issues (continue)

PR NumberSynopsisCategory: Multicast Routing
1863470
Major
The rpd crash due to memory corruption in PIM/MSDP network
Product-Group=junos
On all Junos and Junos Evolved platforms, enabling PIM (Protocol Independent Multicast) or MSDP (Multicast Source Discovery Protocol) may cause a rare memory corruption during the update of the MSDP Source Active route. This issue primarily affects highly scaled environments, leading to rpd (routing protocol daemon) coredumps and potential traffic loss.

Resolved In: evo:22.4R3-S8-EVO evo:23.2R2-S2-J10-EVO evo:23.2R2-S4-EVO evo:23.4R2-S6-EVO evo:24.2R2-S1-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:19.1R3-S15 junos:19.2R3-S12 junos:19.3R3-S13 junos:20.2R3-S11 junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S4 junos:23.4R2-S6 junos:24.2R2-S1 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Multicast for L3VPNs
1888630
Major
MVPN Source PE might incorrectly send mcast traffic on SPT while actual receiver is still on RPTree
Product-Group=junos
In currently flow when a provider tunnel is being deleted, it is assumed the cmcast routes associated to the ptnl would've have been updated before. This is fine for inclusive tunnels, however for selective tunnels especially wild card scenarios the cmcast routes may not be updated. So in cases where the ptnl is deleted like configuration based removal or underlying tunnel going down, there is chance that the forwarding routes are still not deleted. The cmcasts are deleted later in the flow but when they are deleted the corresponding forwarding routes are still not deleted since there is no corresponding ptnl for the cmcast. This will create issues if forwarding is supposed to happen via different forwarding entry like a *, G entry but since the more specific S, G stale entry exists, traffic will hit the later and lead to unexpected behavior like traffic black-holing if S, G is Pruned entry.

Resolved In: evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.2R2-S3 junos:24.4R2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: ACX Timing software
1810429
Major
ACX710 PTP ports marked 'passive' instead of 'master' during T-GM selection
Product-Group=junos
In a scenario where two T-GM devices (Telecom Grandmaster clocks) have identical BMCA (Best Master Clock Algorithm) parameters, except for steps removed or grandmaster ID, the ACX710 running the G.8275.1 profile can experience a failure in proper PTP (Precision Time Protocol) clock synchronization. This issue arises because the default BMCA is used instead of the expected Alternate BMCA profile in G.8275.1. This mismatch leads to incorrect PTP clock states, with master ports being marked as 'Passive' instead of 'Master'.

Resolved In: junos:23.2R2-S3 junos:23.4R2-S8 junos:24.2R2 junos:24.3R1 junos:24.4R1
PR NumberSynopsisCategory: Category for tracking Olympus-MX issues
1906557
Major
While collecting RSI, takes long time to produce output on MX platform
Product-Group=junos
On MX platforms, the cli output for 'show services nat source summary' can take a long time to execute on a highly scaled environment. The issue aggravates when collecting RSI (request support information) and it takes more than an hour for the process to complete. In few instances, this also led to other processes like SNMP monitoring getting stuck.

Resolved In: evo:23.2R2-S6-EVO evo:23.4R2-S7-EVO evo:24.2R2-S4-EVO evo:24.4R2-S3-EVO evo:25.4R1-EVO junos:22.4R3-S10 junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R2 junos:25.2R2-S1 junos:25.4R1
PR NumberSynopsisCategory: "ifstate" infrastructure
1882329
Minor
The management interface is unreachable post switchover/RPD restart events
Product-Group=junos
On all Junos platforms with management interface em0/fxp0 disabled, the management port remains unreachable after performing RE switchover or rpd restart events and re-enabling the management port.

Resolved In: junos:25.4R1
PR NumberSynopsisCategory: Kernel Tunnel Interface Infrastructure
1897240
Major
Chassis-Control restart triggers when configuring GRE interface across multiple routing-instances leading to kernel crash
Product-Group=junos
On Junos series devices, the kernel crash occurs when creating and configuring a identical GRE(Generic Routing Encapsulation) interface across different routing-instances.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S3 junos:24.4R2-S1 junos:24.4R2-S3 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Paradise pfe ddos protection feature
1828196
Major
Error messages are seen due to high CPU utilization
Product-Group=junos
On Junos MX and PTX platforms (non-AFT based), error messages are seen with the operations that involve high CPU utilization on the RE and/or FPC. This issue has no impact on traffic.

Resolved In: junos:19.2R3-S12 junos:19.3R3-S13 junos:20.2R3-S11 junos:22.3X60 junos:22.4R3-S5 junos:22.4X50 junos:23.2R2-S3 junos:23.4R2-S7 junos:24.2R2-S2 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2
PR NumberSynopsisCategory: Express Chip L3 software
1761887
Major
ECMP traffic drop after the AE interface flap
Product-Group=junos
On Junos OS PTX and QFX platforms, in a race condition after the AE (Aggregated Ethernet) interface flap, PFE (Packet Forwarding Engine) will not update unilist next-hops with flapped AE next-hop correctly, causing ECMP (Equal-Cost Multi-Path) traffic drop.

Resolved In: junos:20.3X75-D36 junos:20.4R3-S1-J10 junos:21.4R3-S5-J1 junos:21.4R3-S5-J11 junos:21.4R3-S5-J8 junos:21.4R3-S5-J9 junos:21.4R3-S6 junos:21.4X10 junos:22.1R3-S5 junos:22.2R3-S3 junos:22.3R3-S2 junos:22.3X60 junos:22.4R3 junos:23.2R2 junos:23.4R1 junos:24.1R1
1827286
Major
The icmpv4/v6 ping fails with ddos-protection* icmp configuration
Product-Group=junos
The PTX10008, PTX10002-60C, or QFX10002-60C platforms may not send back ICMPv4/v6 reply packets properly due to defects leading to misprogramming of hardware. Ping with v4/v6 from another device to the PTX10008, PTX10002-60C, or QFX10002-60C platform will fail.

Resolved In: junos:22.4R3-S5 junos:22.4X50
1877538
Major
Multicast traffic loss is seen when MVPN with node protection is enabled
Product-Group=junos
On Junos PTX and QFX10K platforms with node protection enabled on a Multicast Virtual Private Network (MVPN) scenario, multicast traffic loss will be seen when the number of child links in an aggregated ethernet (AE) interface for bypass Label Switched Path (LSP) egress interface is higher than primary LSP and one of the child links goes down on primary LSP egress interface.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:23.4R2-S7 junos:24.2R2-S2 junos:24.4R2
PR NumberSynopsisCategory: Protocol Independant Multicast
1880262
Major
PIM neighbors timeout on backup RE due to inconsistent state with master
Product-Group=junos
On all Junos and Junos Evolved platforms with dual Routing Engines (REs), Protocol Independent Multicast (PIM) neighborship is not be maintained on the backup Routing Engine after a ppmd-agent restart. This can lead to loss of PIM neighbor state on the backup RE.

Resolved In: evo:23.4R2-S6-EVO evo:24.2R2-S2-EVO evo:24.4R2-S4-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2-S4 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Issues related to PKI daemon
1839090
Major
Traffic loss due to tunnel establishment failure in HA setup
Product-Group=junos
On Junos platforms, during PKI (Public Key Infrastructure) certificate renewal in an HA (High Availability) setup, if the PKI daemon on the secondary node is busy, mismatched certificates will occur. If a failover happens, the mismatched certificates are used for IKE (Internet Key Exchange) tunnel establishment, causing tunnel failure and resulting in traffic loss.

Resolved In: evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:24.4R2-EVO junos:23.4R2-S3 junos:23.4R2-S4 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:24.4R2-S1 junos:25.1R1
1892297
Major
The pkid crash is observed during enrolment of device's local certificate through SCEP
Product-Group=junos
On Junos OS platforms that use the pki service (public key Infrastructure) for device's local certificate enrolment via SCEP (Simple Certificate Enrolment Protocol), the pki daemon crashes during the enrolment process due to the user misconfiguration in CA (Certificate Authority) profile, specifically the key-usage of the CA certificate for the CA profile lacks the certificate-signing, resulting in impact to services relying on certificate verification.

Resolved In: junos:19.1R3-S15 junos:19.2R3-S12 junos:19.3R3-S13 junos:20.2R3-S11 junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2 junos:24.4R2-S3 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
1901098
Major
PFE Crash observed platforms where PKI and SSL-Proxy services are configured
Product-Group=junos
In stressful conditions, FPC crash observed and core file generated when PKI (Public key infrastructure) and SSL-Proxy (Secure Sockets Layer) services are configured, on all Junos platforms supporting PKI and SSL-Proxy services (MX, PTX, SRX).

Resolved In: evo:24.4R2-S4-EVO junos:21.4R3-S12 junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S6 junos:23.4R2-S7 junos:23.4X9 junos:24.2R2-S3 junos:24.4R2-S4 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1
PR NumberSynopsisCategory: Periodic Packet Management Daemon
1912250
Major
BFD sessions will not come up on Junos OS and Junos OS Evolved platforms due to keychain names overlapping
Product-Group=junos
On Junos OS and Junos OS Evolved platforms, where BFD with authentication key chain names are overlapping due to which BFD (Bidirectional Forwarding Detection) sessions will not come up in few scenarios like restart bfdd, restart ppmd, restart FPC.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:23.4R2-S6-J1 junos:23.4R2-S7 junos:24.4R2-S3 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: PPPoE functional plugin for bbe-smgd
1868007
Major
PPPoE subscriber login failures observed after interface flapping resulting in AC system errors on Junos MX Platforms
Product-Group=junos
On Junos MX platform with subscriber management enabled, interface flapping causes PPPoE subscriber login failures, resulting in AC (Access Concentrator)System errors.

Resolved In: evo:25.2R1-EVO evo:25.3R1-EVO junos:19.2R3-S12 junos:20.2R3-S11 junos:21.4R3-S12 junos:22.4R2-S1-J6 junos:22.4R3-S7 junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: QFX platform fabric mgmt for Express ASIC chip
1833086
Major
IBM | qfx10008 | 21.4R3-S5.4 | FPC 0 SIB Link Error | Link error is reported even with lower threshold
Product-Group=junos
CRC errors can be seen because of the HW degrading with age. Although the CRC errors are not crossing the threshold but links report error. The patch has been added to address such event with additional logs.

Resolved In: evo:24.4R2-EVO evo:25.1R1-EVO junos:21.4R3-S10 junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: QFX L3 data-plane/forwarding
1886612
Major
Next-hop entries are not getting programmed in ECMP unilist group after device upgrade
Product-Group=junos
On Junos OS QFX5k and EX4k platforms, when static ECMP (Equal-Cost Multi-Path) is configured, traffic loss will be observed due to a next-hop programming issue. The device fails to install the next-hop entries in hardware for static ECMP routes, resulting in traffic not being forwarded as expected after a device upgrade.

Resolved In: junos:22.4R3-S8 junos:23.4R2-S6 junos:23.4R2-S7 junos:23.4X4 junos:24.4R2 junos:25.2R2 junos:25.2R2-S1 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: QFX EVPN / VxLAN
1856424
Major
The dcpfe process crashes on specific Junos QFX and EX platforms due to memory corruption
Product-Group=junos
A memory corruption issue can result random dcpfe (dense concentrator packet forwarding engine) process crashes on specific Junos QFX and EX platforms configured with VXLAN (Virtual Extensible Local Area Network) configuration.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.2R2-S3 junos:24.4R2 junos:24.4R2-S1 junos:24.4R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
1878555
Major
Transit unicast ARP requests are dropped instead of being forwarded
Product-Group=junos
On Junos QFX5K and EX46xx platforms, in an Ethernet VPN-Virtual Extensible LAN (EVPN-VXLAN) environment, when "no-arp-trap" is enabled, transit unicast Address Resolution Protocol (ARP) packets that are not destined for the local switch Integrated Routing and Bridging Media Access Control (IRB MAC) are dropped instead of being forwarded across the leaf nodes.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S5 junos:23.4R2-S6 junos:23.4R2-S7 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: QFX5K JUNOS Interface, MACSec, Optics, SDK, PHY
1845045
Major
On QFX5120-48YM port remains down when speed shifts from 1G to 10G
Product-Group=junos
On QFX5120-48YM, if a port is transitioned directly from 1G to 10G either by swapping the SFP or by changing port and chassis speed settings without intermediate reset. The 10G link will remain down.

Resolved In: junos:22.4R3-S8 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1
1890867
Major
QFX5120 - SFP+ Modules disappear/down post upgrade
Product-Group=junos
On QFX5120-48T platforms, QSA-SFP+ adapter(100G/40G ) modules disappear/go down after software upgrade. Due to unsupported QSA usage in the impacted release, which will trigger a dcpfe (Dataplane Packet Forwarding Engine) crash.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: QFX5200/5110/5120/5210 Platfom issues
1882472
Major
JMA package fails to initialise after a power cycle on EX4650/QFX-5E series devices
Product-Group=junos
On Junos EX4650/QFX-5E series, after installing the JMA(Junos Mist Agent) package, a graceful reboot (using request system reboot or request system halt) is required to commit the changes. An abrupt power cycle before a graceful reboot causes the system to lose the installed JMA package.

Resolved In: junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: MPC5E, MPC6E specific timing and synchronization
1872093
Major
SyncE clock event stuck at "Clock abort" and PTP stops working on all Junos and Junos OS Evolved platforms
Product-Group=junos
Initial FSM design augmented to handle internal recovery from SyncE clock abort, if and only if, it took longer than 30secs for clksyncd to receive SyncE clock qualification message form the PFE. In all other SyncE clock abort cases, recovery is possible externally as specified under Workaround. This is not a bug but enhancement in FSM design.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: Issues related to krt-async routing infrastructure
1866522
Major
VPLS session stays down after interface flaps
Product-Group=junos
An LSI IFL remains in RPD even after being deleted by the interface manager daemon. It is visible in show interface routing but not in show interfaces, indicating that RPD still holds the IFL despite its removal elsewhere. rpd-agent does not send a delete message to RPD due to a reference count issue. Another daemon?likely l2ald?still holds a reference to the IFL. rpd-agent only sends the delete once all references are cleared, which doesn't happen in this case. The fix is to send a "delete pending" message from rpd-agent to RPD. RPD will treat this as a delete and remove the IFL, ensuring consistency across the system.

Resolved In: evo:23.2R2-S5-EVO evo:23.2X2-EVO evo:23.4R2-S8-EVO evo:24.2R2-S4-EVO evo:24.4R2-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:26.2R1-EVO junos:23.4R2-S8 junos:25.2R2 junos:25.3R1
PR NumberSynopsisCategory: RPD Next-hop issues including indirect, CNH, and MCNH
1848971
Major
Configuring BGP rib-sharding and generate route will cause rpd process to crash
Product-Group=junos
On Junos and Junos OS Evolved platforms, configuring BGP (Border Gateway Protocol) rib-sharding and generate routes will cause the rpd process to crash.

Resolved In: evo:23.2R2-S4-EVO evo:24.2R2-EVO evo:24.4R1-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:22.4R3-S6 junos:23.2R2-S4 junos:23.4R2-S6 junos:24.2R2 junos:24.4R1 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Shard routing infrastructure within RPD
1757915
Major
The rpd process crashes when processing multipath routes with mixed indirect and composite next-hops under rib-sharding
Product-Group=junos
On all Junos and Junos OS Evolved platforms, when rib-sharding is enabled and RT (Route Target) multipath routes containing both indirect and composite next-hop types are processed, the rpd (Routing Protocol Daemon) process will crash due to incorrect handling during the next-hop copy operation from RIB (Routing Information Base) shards to the main RIB thread. An rpd crash results in all routing protocols going down and causes a brief traffic disruption until the rpd process restarts.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:23.2R2-S2-J9 junos:23.4R2-S5 junos:24.4R2-S2-J8 junos:24.4R2-S3 junos:25.2R2 junos:25.2R2-S1 junos:25.3R1 junos:25.4R1 junos:25.4R2 junos:26.1DCB
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1842654
Major
RPD process crash observed with dynamic tunnel configuration with overlap in destination networks under APP based and NHB mode and rollback
Product-Group=junos
On all Junos and Junos OS Evolved platforms the rpd (Routing Protocol Daemon) process will crash when dynamic tunnels are configured with overlap in destination networks under APP (Application-based tunnels) based and NHB (Next Hop Based) mode and rollback after some time.

Resolved In: evo:22.3X80-D47-EVO evo:22.3X80-D49-EVO evo:23.4R2-S4-EVO evo:24.2R2-EVO evo:24.4R2-EVO evo:25.1R1-EVO junos:21.4R3-S3-J16 junos:22.4R2-S2-J9 junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1
1860786
Major
BGP queue deadlock on Junos/Junos OS Evolved/cRPD platforms leading to route advertisement failure and traffic loss
Product-Group=junos
On all Junos, Junos OS Evolved, and cRPD platforms, due to deadlock in internal processes, BGP (Border Gateway Protocol) route advertisement fails leading to traffic disruption.

Resolved In: evo:22.3X80-D49-EVO evo:23.2R2-S4-EVO evo:23.4R2-S3-J14-EVO evo:23.4R2-S4-J2-EVO evo:23.4R2-S5-EVO evo:23.4X100-D40-EVO evo:24.2R2-S1-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:20.3X75-D442 junos:20.3X75-D52 junos:21.4R3-S10-J4 junos:21.4R3-S12 junos:22.3X60 junos:22.4R3-S7 junos:22.4R3-S8 junos:22.4X50 junos:23.2R2-S4 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Resource Reservation Protocol
1864949
Major
User traffic dropped after ISIS went down on one side with trapcode observed
Product-Group=junos
On all Junos and Junos OS Evolved platforms if a link along the path of a Label Switched Path (LSP) flaps briefly such that the router at upstream end of the flapping link does not detect the link down but only the router at the downstream end does, then the upstream router does not undertake necessary actions, like generating ResvTear message, that should be taken after next-hop link down. This will result in unexpected traffic blackholing on the router at the downstream end of the flapping link.

Resolved In: evo:22.3X80-D49-EVO evo:22.4R3-S7-EVO evo:23.2R2-S4-EVO evo:23.4R2-S4-J2-EVO evo:23.4R2-S5-EVO evo:24.2R2-S4-EVO evo:24.4R2-EVO evo:24.4X200-D10-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S5 junos:24.2R2-S4 junos:24.2R2-S5 junos:25.2R1 junos:25.3R1
1866944
Major
Traffic blackholing in LSPs due to link failure before protection signalling is processed
Product-Group=junos
On all Junos and Junos OS Evolved platforms, traffic blackholing occurs on MPLS (Multi-Protocol Label Switching) Label Switched Paths (LSPs) when link protection is enabled, under specific conditions during link failure events that occur just after the LSP is established.

Resolved In: evo:23.2R2-S5-EVO evo:23.4R2-S5-EVO evo:24.2R2-S4-EVO evo:24.4R2-EVO evo:24.4R2-S1-J1-EVO evo:24.4R2-S4-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:20.3X75-D441 junos:20.3X75-D442 junos:20.3X75-D52 junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:22.4R3-S9 junos:23.2R2-S5 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.2R2-S4 junos:24.4R2 junos:24.4R2-S4 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1
1881906
Major
BFD session failure causes LSP to go down and the inactive route remains in the routing table leads to traffic black hole
Product-Group=junos
On Junos OS and Junos OS Evolved platforms, when an RSVP (Resource Reservation Protocol) LSP (Label Switched Path) goes down due to a failure in the associated BFD (Bidirectional Forwarding Detection) session, and the corresponding route remains in the routing/forwarding table causing traffic black-holing. If there are other active LSPs to the same destination, those active routes are preferred over the inactive route associated with the failed LSP.

Resolved In: evo:24.4R2-EVO evo:25.2R2-EVO evo:25.3R1-EVO junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.2R2 junos:25.3R1
1893822
Major
Record Route Object displayed in show mpls lsp output is trucated if number of hops is sixteen or more
Product-Group=junos
If the number of RSVP LSP hops is sixteen or higher, the RRO displayed in show mpls lsp extensive output may get truncated

Resolved In: evo:23.4R2-S4-J2-EVO evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S7 junos:24.2R2-S3 junos:24.4R2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
1896022
Major
More bandwidth admitted onto a TE link when Label Switched Paths (LSPs) undergoing make-before-break re-route over the same link carrying the bypass LSP during local repair
Product-Group=junos
On all Junos and Junos evolved platforms with Point of Local Repair Router, in a Multiprotocol Label Switching(MPLS) Label Switched Paths (LSPs) set-up if the ingress router is configured with link-protection , if Label Switched Paths (LSPs) undergo local repair and subsequently undergo global repair in make-before-break fashion such that the LSPs are re-routed over the same TE link that carries the bypass LSP that protect the LSPs during local repair, then more re-routed LSPs may be admitted on the TE link carrying the bypass LSP than that should be admitted. This may result in some re-routed LSPs remaining on the TE link causing additional traffic sent on the TE link than the capacity of the TE link.

Resolved In: evo:23.2R2-S6-EVO evo:23.4R2-S4-J2-EVO evo:24.2R2-S3-EVO evo:24.4R2-S1-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:22.4R3-S7-J1 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S3 junos:24.4R2-S1 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Issues related to control plane security
1865633
Major
Junos OS: A low-privileged user can escalate their privileges so that they can log in as root (CVE-2026-21916)
Product-Group=junos
A UNIX Symbolic Link (Symlink) Following vulnerability in the CLI of Juniper Networks Junos OS allows a local, authenticated attacker with low privileges to escalate their privileges to root, which will lead to a complete compromise of the system. Please refer to https://supportportal.juniper.net/JSA107807 [juniper.net] for more information.

Resolved In: evo:25.2R2-EVO junos:20.2X42 junos:21.2R3-S11 junos:21.2X33 junos:21.4R3-S10-J4 junos:21.4R3-S10-J4-X1 junos:22.4R3-S7-J1 junos:23.2R2-S6 junos:23.4R2-S6 junos:23.4R2-S7 junos:23.4X12 junos:23.4X13 junos:23.4X30 junos:23.4X30-D30 junos:24.2R2-S3 junos:24.2R2-S4 junos:24.2X1 junos:24.2X4 junos:24.2X50 junos:24.4R2-S1 junos:24.4R2-S1-C1 junos:24.4R2-S2 junos:25.2R1-S1 junos:25.2R1-S2 junos:25.2R2
PR NumberSynopsisCategory: SNMP Infrastructure (snmpd, mib2d)
1854093
Major
SNMP INFORM handling issue due to routing-instance-based trap source socket
Product-Group=junos
On Junos platform, Improved SNMPv3 INFORM handling to ensure messages are evenly distributed across all configured trap targets.

Resolved In: junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
1906718
Critical
Junos OS and Junos OS Evolved: CVE-2022-24805 resolved in net-SNMP
Product-Group=junos
CVE-2022-24805 has been resolved in net-SNMP software included with Juniper Networks Junos OS and Junos OS Evolved. Please refer to https://supportportal.juniper.net/JSA107822 [juniper.net] for more information.

Resolved In: evo:23.2R2-S4-J2-EVO evo:23.2R2-S6-EVO evo:23.4R2-S4-J2-EVO evo:23.4R2-S7-J12-EVO evo:23.4R2-S8-EVO evo:24.2R2-S4-EVO evo:24.4R2-S1-J1-EVO evo:24.4R2-S3-EVO evo:24.4R2-S3-J1-EVO evo:24.4R2-S4-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.4R1-EVO evo:26.1R1-EVO junos:19.2R3-S12 junos:19.3R3-S13 junos:19.4R3-S16 junos:20.3X75-D52 junos:21.2X33 junos:21.4R3-S10-J4 junos:22.3X60 junos:22.4R3-S7-J1 junos:22.4R3-S9 junos:22.4X50 junos:23.2R2-S6 junos:23.4R2-S7 junos:23.4R2-S8 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: Generic platform and infra issues for MS-MIC and MS-MPC(XLP)
1901021
Major
Service-Set Configuration Bug Leading to Kernel Panic on Junos MX
Product-Group=junos
On Junos MX platforms with MS-MPC, when new rules are added to a service-set, the configuration size increases incrementally. This growth will cause failures during the commit process, potentially leading to a kernel panic. As a result, new configurations may not be successfully applied.

Resolved In: evo:25.2R2-EVO evo:25.4R1-EVO junos:21.2X33 junos:25.2R2 junos:25.4R1
1903211
Minor
Vmcore triggers while configuring new members into an existing AMS interface on all MX platforms with specific linecard
Product-Group=junos
On all MX platforms with MS-MPC(Multiservices Modular PIC Concentrator) card, When new members are configured into an existing AMS (Aggregated Multiservices) interface, it causes all the PICs (Physical Interface Cards) to bounce, which triggers a vmcore and RE(Routing Engine) reboot due to a timing rare-issue.

Resolved In: evo:26.1R1-EVO junos:23.4R2-S8 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: SFW, CGNAT on MS-MIC/MS-MPC (XLP)
1869450
Major
Subscribers failed to establish DS-Lite softwires due to stale softwire entries
Product-Group=junos
On Junos MX Series platforms using MS-MPC or MX-SPC3 line cards with DS-Lite softwires subscriber services and the session-limit-per-prefix option enabled, the softwire extension reference count will not be properly decremented during subscriber session teardown. These stale softwire entries cause traffic failures when the same subscriber connects to a different AFTR (Address Family Transition Router). This will not impact new subscriber sessions with any AFTR, nor will it affect existing subscriber sessions with the same AFTR.

Resolved In: junos:22.4R3-S7-J2 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Segment routing traffic Engineering
1860334
Major
A momentary drop in traffic is observed when changes are applied on multipath SR-TE LSPs
Product-Group=junos
On all Junos and Junos OS EVO (Evolved) platforms, when using SR-TE (Segment Routing-Traffic Engineering) LSP (Label-Switched Path) within a multipath container, a configuration or state change (Eg: modifying the maximum-ecmp value) or a change to the segment-list on one SR-TE LSP, may impact other LSP traffic which are pointing to the same BGP Protocol next-hop. During such event, SR-TE routes are temporarily moved to a hidden state, leading to brief traffic disruption. This occurs because SR-TE is populating route parameters with an unusable next-hop.

Resolved In: evo:23.2R2-S4-EVO evo:23.4R2-S8-EVO evo:24.2R2-S2-EVO evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:21.2R3-S6-J26 junos:23.2R2-S4 junos:23.4R2-S8 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S4 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: all ipv6 flow bugs on srx platforms
1807541
Major
SRX4600 with SOF is observed to continue sending ipv6 traffic out a downed member link.
Product-Group=junos
If a bundled member link is removed either physically (cable disconnection) or by configuration (admin down), it may be observed that ipv6 traffic is continuing to send out that downed link.

Resolved In: junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S3 junos:23.4R2-S4 junos:24.2R2 junos:24.4R1 junos:25.1R1 junos:25.3R1
PR NumberSynopsisCategory: SRX branch platforms
1889549
Major
The XE interfaces of SRX380 platform with 1G SFP (fiber) are flapping continuously when LACP is enabled
Product-Group=junos
When LACP (Link Aggregation Control Protocol) is enabled using 1G SFP(Small Form-factor Pluggable)-fiber (such as SFP-SX, SFP-LX etc) over XE interfaces, frequent state transitions will repeatedly trigger configuration updates. Due to LACP instability, the interfaces will continuously flap. As a result, the port configuration will be re-applied automatically which leads to a loop of re-configurations until the LACP state stabilizes.

Resolved In: junos:23.2R2-S7 junos:23.4R2-S8 junos:24.2R2-S3 junos:24.4R2-S3 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
1895179
Major
The kern.maxfiles limit exceeded observed due to log rotation resulting in unresponsive SSH
Product-Group=junos
On all Junos OS platforms, Configuring multiple syslog servers causes duplicate routing-instance map entries, leading to an eventd file descriptor leak during log rotations. Once the threshold is exceeded, the SSH connection becomes unresponsive.

Resolved In: junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S6 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S2 junos:25.2R2
1905219
Critical
The traffic on all interfaces of SRX300/SRX320 platforms are dropped while an interface of them is receiving pause frames from connecting device
Product-Group=junos
While an interface of SRX300/SRX320 is receiving pause frames from connecting device, all incoming and outgoing traffic on all interfaces of SRX300/SRX320 was dropped unexpectedly. This issue only occurs when the interface with 'auto-negotiation' disabled receives pause frame. This issue occurs because disabling 'auto-negotiation' causes both 'pause frame' and 'Tx/Rx pause frame' to be set to 'yes'. Connecting device is sending pause frames due to hardware failure.

Resolved In: junos:19.4R3-S16 junos:21.2R3-S11 junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S7 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: MPC7/8/9 Interface Issues
1869285
Major
Speed conversion from 10G to 1G on MX routers with MPC7E-10G does not synchronise across PFE and Kernel when adding the interface to Aggregate Ethernet (AE)
Product-Group=junos
On MX Series routers with MPC7E-10G line cards when interface speed is converted to 1G and the interface is added to AE, speed change is not getting synchronised across Packet Forwarding Engine (PFE) and Kernel, leading to inconsistencies in bandwidth reporting and Class of Service (CoS) behaviour. Using 'set interfaces speed 1g', ensures proper synchronisation across all modules.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:19.4R3-S16 junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S5 junos:24.2R2-S3 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: MX10003/MX204 MPC defects tracking
1886937
Major
Interfaces either fail to come up or flap or a delay is observed on MX10003 platforms when the interface is reset or the devices is restarted
Product-Group=junos
On MX10003 platforms peering to third-party devices, interfaces remain down or flap or a delay is observed while it comes back up after the device is restarted or the Flexible PIC Concentrator (FPC) is restarted or when the interface is reset. The symptoms is not consistent and any of the mentioned behaviour could be seen. Due to the interface going down or in case of a flap/delay, services running over the interface will be impacted or traffic flowing through that interface will be dropped.

Resolved In: junos:19.1R3-S15 junos:20.2R3-S11 junos:21.4R3-S12 junos:22.4R3-S8 junos:23.2R2-S3-J18 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2-S1 junos:24.4R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: ZT/YT pfe infra issues
1885754
Major
MX304 LNS: FPC restart and aft-trio core after LMIC OIR when SI pool spans both MICs
Product-Group=junos
On MX304 routers acting as LNS, an FPC restart and aftd-trio core may occur if a MIC is offlined (LMIC OIR) while the service-device pool of SI interfaces spans both MICs on the same FPC. This may result in transient loss of subscriber sessions and service impact.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:24.4R2 junos:24.4R2-S2 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: ZT/YTpfe bridging, learning, stp, oam, irb software
1871698
Major
Filter-Based Forwarding (FBF) failed for over unicast IRB over AE on MX and EX platforms
Product-Group=junos
On all Junos MX with MPC10, MPC11, MX304 and EX92K platforms, when Integrated routing and bridging (IRB) interface is configured over Aggregate Ethernet (AE), the packet is received on an l3 IRB which is processed through a filter based forwarding (FBF) which forwards the traffic over an IRB which has an underlay as L2 AE interface. When the packet is forwarded over the l2 AE, the packet gets dropped because the egress PFE calculation is incorrect resulting in a traffic drop.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:21.4R3-S12 junos:22.2R3-S7 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S3-J21 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: ZT/YT pfe multicast software
1912465
Major
Multicast traffic not forwarded to AE member interfaces when Multicast Latency Fairness feature is enabled
Product-Group=junos
On all MX platforms using MPC10, MPC11, LC4800, LC9600, MPC10E-10C, or MPC10E-15C line cards, multicast traffic is not forwarded to Aggregated Ethernet (AE) member interfaces when the Multicast Latency Fairness (MLF) feature is enabled.This issue occurs when the multicast downstream list includes AE interfaces along with two or more physical downstream interfaces located on different Packet Forwarding Engines (PFEs).

Resolved In: evo:25.4R1-EVO evo:26.1R1-EVO junos:23.4R2-S4-J35 junos:23.4R2-S7 junos:25.2R2 junos:25.4R1 junos:26.1R1
PR NumberSynopsisCategory: Trio pfe stateless firewall software
1837840
Major
Incorrect color-aware srTCM marking with yellow packet loss priority
Product-Group=junos
There was a software side limitation on the highest CBS that can be configured for MPCs that have LU type lookup chips due to a hardware PR. The Hardware PR was resolved in MX240/ MX480/ MX960/ MX2008/ MX2010/ MX2020/ MX10003/ MX10008/MX10016/ EX9200/EX9204/EX9208/ EX9214/ EX9251/EX9253/ SRX5400/SRX5600/SRX5800 platforms, but the software-side limitation was not removed for the same. Due to this limitation, whenever the CBS was configured above its limit (earlier 33m), the low-level parameters used to get configured such that the packets would not have any credits available, resulting in them getting marked as RED.

Resolved In: junos:22.2R3-S7 junos:22.4R3-S6-J2 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R1 junos:24.4R1-S3 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Trio pfe bridging, learning, stp, oam, irb software
1874503
Major
An IPv6 neighbor solicitation packet is dropped at the ingress PE router when it is received with more than two VLAN tags.
Product-Group=junos
On Junos platforms having 'arp-supression' suppression enbabled, when IPV6 neighbor solicitation packets are received with more than two tags in an EVPN (EThernet Virtual Private Network) instance, the NDP (Neighbour Discovery Protocol) packets that are suppressed to the host path are incorrectly processed through a wrong DDOS policer, as the hop-limit value from the IPV6 header is not properly retrieved, causing them to be dropped by the packet forwarding engine.

Resolved In: junos:22.2R3-S7 junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: Trio pfe l3 forwarding issues
1891110
Major
A GRE tunnel configured with a tunnel key drops MPLS-encapsulated traffic
Product-Group=junos
On MX platforms with line cards MPC1-9, a Generic Routing Encapsulation (GRE) tunnel configured with a tunnel key drops Multi-Protocol Label Switching (MPLS) encapsulated traffic as it is unable to find the key.

Resolved In: junos:22.4R3-S9 junos:23.2R2-S5 junos:23.4R2-S7 junos:24.2R2-S3 junos:24.4R2-S3 junos:25.2R1-S1 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Authentication, Authorization, Accounting, PAM (RADIUS/tacplus)
1850776
Critical
Multiple Products: RADIUS protocol susceptible to forgery attacks (Blast-RADIUS) (CVE-2024-3596)
Product-Group=junos
An Authentication Bypass by Spoofing vulnerability in the RADIUS protocol of Juniper Networks Junos OS and Junos OS Evolved platforms allows an on-path attacker between a RADIUS server and a RADIUS client to bypass authentication when RADIUS authentication is in use. Please refer to https://supportportal.juniper.net/JSA88210 [juniper.net] for more information.

Resolved In: junos:19.2R3-S12 junos:19.2R3-S13 junos:19.3R3-S13 junos:21.2R3-S11 junos:21.4R3-S10 junos:21.4R3-S10-X1 junos:22.2R3-S6 junos:22.4R3-S6 junos:23.2R2-S3 junos:23.4R2-S8 junos:24.2R2-S5 junos:24.4R2-S4
PR NumberSynopsisCategory: Junos Automation, Commit/Op/Event and SLAX
1872284
Major
master-eventd will fail after multiple RE switchover
Product-Group=junos
On Junos and Junos OS Evolved platforms with dual RE(Routing Engine) , master-eventd will fail to start after multiple RE switchovers when event-options policies are configured. This happens only if a process is still waiting for an action (like file transfer or SSH) to complete.

Resolved In: evo:23.4R2-S6-EVO evo:25.2R1-S2-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:19.2R3-S12 junos:19.3R3-S13 junos:20.2R3-S11 junos:22.4R3-S9 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: Configuration management, ffp, load action
1671112
Major
Test Configuration will fail even though the configuration file is having valid configurations
Product-Group=junos
On all Junos and Junos Evolved platforms, while executing the test configuration, the test configuration might fail even though the configuration file is having valid configurations.

Resolved In: evo:21.4R3-S7-EVO evo:22.2R2-J4-EVO evo:22.2R2-J6-EVO evo:22.2R2-S2-EVO evo:22.2R3-EVO evo:22.3R1-S2-EVO evo:22.3R2-EVO evo:22.3R3-EVO evo:22.4R1-EVO evo:22.4R1-S1-EVO evo:22.4R2-EVO evo:23.1R1-EVO evo:23.2R1-EVO junos:21.2R3-S7 junos:21.2X32-D20 junos:21.2X32-D30 junos:21.2X33 junos:21.2X8 junos:21.2X9 junos:21.4R3-S6 junos:21.4R3-S6-X1 junos:21.4X7 junos:22.1R3-S1 junos:22.2R2-S1 junos:22.2R2-S2 junos:22.2R3 junos:22.3R1-S2 junos:22.3R2 junos:22.3R3 junos:22.4R1 junos:22.4R1-S1 junos:22.4R2 junos:23.1R1
1854461
Major
Configured TFTP server connection and rate limits are not applied
Product-Group=junos
On all Junos and Junos Evolved platforms configured as Trivial File Transfer Protocol (TFTP) server , "connection-limit" or "rate-limit" values are not updated as per configured values.

Resolved In: evo:23.2R2-S7-EVO evo:24.2R2-S3-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:20.3X75-D442 junos:22.2R3-S7 junos:23.2R2-S7 junos:23.4R2-S6 junos:23.4R2-S8 junos:24.2R2-S3 junos:24.4R2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: Configuration mgmt, ffp, load-action, commit processing
1751574
Major
Netconf RPC commit fails due to commit warning received for unprotect operation, CLI commit completes with warning
Product-Group=junos
In Netconf private edit configuration session, commit RPC fails when unprotect operation is performed.

Resolved In:
PR NumberSynopsisCategory: UI Infrastructure - mgd, DAX API, DDL/ODL
1514927
Critical
Junos OS: EX4600 Series and QFX5000 Series: An attacker with physical access can open a persistent backdoor (CVE-2025-59957)
Product-Group=junos
An Origin Validation Error vulnerability in an insufficient protected file of Juniper Networks Junos OS on EX4600 Series and QFX5000 Series allows an unauthenticated attacker with physical access to the device to create a backdoor which allows complete control of the system. Please refer to https://supportportal.juniper.net/JSA103146 [juniper.net] for more information.

Resolved In: evo:22.3R1-EVO junos:20.3X75-D441 junos:21.4R3 junos:21.4R3-S6 junos:22.2R3-S3 junos:22.3R1 junos:23.4R2 junos:24.2R2 junos:24.3R1
1842868
Major
XML namespace string in rpc-reply tag for system-uptime-information was changed to represent the full version name.
Product-Group=junos
XML namespace string in rpc-reply tag for system-uptime-information was changed to represent the full version name.

Resolved In: evo:23.2R2-S5-EVO evo:24.4R2-EVO evo:25.1R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S4 junos:24.2R2 junos:24.4R2 junos:25.1R1
1872703
Major
Junos OS: Privileged local user can gain access to a Linux-based FPC as root (CVE-2025-30650)
Product-Group=junos
A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root. Please refer to https://supportportal.juniper.net/JSA107863 [juniper.net] for more information.

Resolved In: evo:23.2R2-S4-J2-EVO evo:23.4R2-S4-J2-EVO evo:23.4R2-S8-EVO evo:24.4R2-S1-J1-EVO evo:24.4R2-S3-EVO evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:19.2R3-S12 junos:20.3X75-D442 junos:20.3X75-D52 junos:21.2R3-S11 junos:21.2X34 junos:21.4R3-S10-J4 junos:21.4R3-S10-J6 junos:22.4R3-S7-J1 junos:22.4R3-S8 junos:22.4R3-S9 junos:22.4X50 junos:23.2R2-S3-J20 junos:23.2R2-S6 junos:23.4R2-S4-J26 junos:23.4R2-S4-J27 junos:23.4R2-S5 junos:23.4R2-S5-J17 junos:23.4R2-S6 junos:23.4R2-S8 junos:24.2R2-S3 junos:24.2X1 junos:24.4R2 junos:24.4R2-S3 junos:25.2R2 junos:25.4R1
1914952
Minor
The error message will be seen on CLI when 'clear log messages' command is issued
Product-Group=junos
On Junos platforms with BSD6 image, Error message will be seen on CLI when clear log messages command is issued.

Resolved In: evo:25.2R2-EVO evo:26.1R1-EVO junos:22.3X60 junos:23.2R2-S6 junos:24.2R2-S4 junos:24.4R2-S3 junos:25.2R2 junos:26.1R1
PR NumberSynopsisCategory: Issues related to Logging/Tracing, errmsg, eventd infrastruc
1848106
Major
The eventd process crash occurs due to flooding of out of memory logs
Product-Group=junos
On all Junos and Junos OS Evolved platforms, eventd process crashes is observed. This happens when eventd process is processing the flooding of out of memory logs generated by any of the processes running on FPC (Flexible PIC Concentrator). This is traffic impacting depending on the process with memory issues.

Resolved In: evo:22.3X80-D49-EVO evo:22.4R3-S8-EVO evo:23.2R2-S5-EVO evo:23.4R2-S4-EVO evo:24.4R2-EVO evo:25.1R1-EVO evo:25.2R1-EVO junos:22.4R3-S8 junos:23.2R2-S5 junos:23.4R2-S4 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:24.4R2-S2 junos:25.1R1 junos:25.2R1
PR NumberSynopsisCategory: web filterig issues
1854519
Major
FPC crashing when web filtering type set to "juniper-enhanced" or "NG-juniper"
Product-Group=junos
On all SRX platforms, when the web-filtering type set to "juniper-enhanced" or "NG-juniper" (NextGen-juniper), it might cause FPC (Flexible Port Concentrator) card crash and with "srxpfe" or "lcore" crash files generated.

Resolved In: junos:22.2R3-S7 junos:22.4R3-S7 junos:23.2R2-S4 junos:23.4R2-S3-J23 junos:23.4R2-S5 junos:23.4X30 junos:23.4X30-D30 junos:24.2R2-S1 junos:24.4R1-S2-J5 junos:24.4R1-S3 junos:24.4R2 junos:25.1R1 junos:25.2R1 junos:25.3R1
1876037
Critical
Junos OS: SRX Series: Specifically malformed SSL packet causes FPC crash (CVE-2026-21917)
Product-Group=junos
An Improper Validation of Syntactic Correctness of Input vulnerability in the Web-Filtering module of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). Please refer to https://supportportal.juniper.net/JSA105996 [juniper.net] for more information.

Resolved In: junos:23.2R2-S5 junos:23.4R2-S5 junos:23.4X30 junos:23.4X30-D30 junos:24.2R2-S2 junos:24.4R1-S2-J5 junos:24.4R1-S3 junos:24.4R2 junos:25.2R1 junos:25.3R1
1887814
Minor
SNMP polling leaks memory in the UTM daemon ultimately leading to a crash
Product-Group=junos
On all SRX platforms, the memory leak is observed in the Unified Threat Management Daemon (utmd) due to continuous Simple Network Management Protocol (SNMP) polling which ultimately leads to utmd process crash.

Resolved In: junos:19.1R3-S15 junos:19.2R3-S12 junos:19.3R3-S13 junos:19.4R3-S16 junos:20.2R3-S11 junos:21.4R3-S12 junos:22.4R3-S9 junos:23.2R2-S6 junos:23.4R2-S6 junos:24.2R2-S3 junos:24.4R2-S2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: MX10K linecard
1865576
Major
Due to race condition the FPC on MX platform crashes
Product-Group=junos
On all MX platforms with LC480, LC2101, and LC2103 a crash file is generated, resulting in the ukern rebooting and a complete reboot of the LC.

Resolved In: evo:24.4R2-EVO evo:25.2R1-EVO evo:25.3R1-EVO junos:21.4R3-S12 junos:22.4R3-S6-J8 junos:22.4R3-S7 junos:23.2R2-S5 junos:23.4R2-S4 junos:23.4R2-S4-J3 junos:23.4R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:24.4R2-S1 junos:25.1R1 junos:25.2R1 junos:25.3R1
PR NumberSynopsisCategory: VMHOST platforms software
1827549
Major
Large number of memory errors which slows down the system
Product-Group=junos
On all Junos that runs on VMHOST based Routing Engine, when the primary Routing Engine faces a continuous stream of correctable ECC errors, although these errors are individually handled by the hardware, their high frequency over time causes the control plane (Junos VM) on the Routing Engine to slow down and become partially unresponsive. Because of this degraded state, the backup Routing Engine can not take over control in time, delaying the GRES switchover. As a result, the system loses synchronization, all line cards reboot, and traffic disruption occurs.

Resolved In: evo:25.3R1-EVO junos:25.3R1
PR NumberSynopsisCategory: QFX10002 Platform
1869232
Major
CRC errors increase continuously after interface flap on some 100G transceivers with Rx CDR LOL support
Product-Group=junos
On Junos PTX10002-60C, and QFX10002-60C platforms, when using 100G QSFP modules with Clock and Data Recovery Loss of Lock (CDR LOL) support, CRC errors have been observed on odd-numbered ports, leading to traffic disruptions.

Resolved In: junos:22.4R3-S9
PR NumberSynopsisCategory: usf flow and datapath issue on SPC3
1882490
Minor
BFD fail to establish over an IPsec tunnel on Juniper MX Series with the SPC3
Product-Group=junos
On Juniper MX Series platforms equipped with Services Processing Card version 3 (SPC3), Bidirectional Forwarding Detection (BFD) session establishment over an Internet Protocol Security (IPsec) tunnel may fail due to an unintended Time to Live (TTL) decrement on self-generated BFD traffic.

Resolved In: junos:21.4R3-S13 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.4R2 junos:25.2R1-S2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: usf ipsec related issues
1876801
Major
IPsec-inside-IPsec tunnel establishment fails on MX platforms with SPC3 cards
Product-Group=junos
On MX platforms equipped with SPC3 cards, the establishment of the inner IPsec tunnel fails in an IPsec-inside-IPsec tunnel setup. This occurs because the service PIC's forwarding process incorrectly attempts to punt IKE packets to the Route Engine (RE) and cannot resolve the required internal fabric path.

Resolved In: junos:22.4R3-S8 junos:22.4X6 junos:23.2R2-S5 junos:24.2R2-S2 junos:24.4R2 junos:25.2R1 junos:25.3R1
1884595
Minor
Allow default route to be created provided st0 IFL is in a non-default routing instance.
Product-Group=junos
ARI now allows default route to be pushed if the corresponding st0 interface is configured in a specific routing instance.

Resolved In: evo:25.2R2-EVO evo:25.3R1-EVO evo:25.4R1-EVO junos:23.2R2-J23 junos:23.2R2-J25 junos:23.2R2-S5 junos:23.4R2-S6 junos:24.2R2-S2 junos:24.4R2 junos:25.2R2 junos:25.3R1 junos:25.4R1
PR NumberSynopsisCategory: usf nat related issues
1881192
Major
NAT Pool Installation failure due to Service-Set name length mismatch
Product-Group=junos
On MX240, MX480, and MX960 platforms with SPC3 ( Services Processing Card 3 ) , new NAT ( Network Address Translation ) pools may fail to install, this is due to a mismatch in service-set name length handling. The system stores only 32 characters for service-set information, causing failures when names exceed this limit.

Resolved In: evo:25.4R1-EVO junos:19.1R3-S15 junos:19.2R3-S12 junos:19.3R3-S13 junos:20.2R3-S11 junos:23.2R2-S7 junos:24.2R2-S5 junos:24.4R2-S4 junos:25.2R1-S2 junos:25.2R2 junos:25.4R1 junos:26.1R1

 

Modification History

First publication 2026-05-11