CVE-2026-101283: Esnet IPERF3

Critical severity, CVSS 9.2. EPSS: 0.3% chance of exploitation in the next 30 days.

iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22

Affected products

  • Esnet IPERF3: version 3.20 only; version 3.21 only

Published 2026-09-30. Last modified 2026-10-01.