CVE-2026-101283: Esnet IPERF3
Critical severity, CVSS 9.2. EPSS: 0.3% chance of exploitation in the next 30 days.
iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22
Affected products
- Esnet IPERF3: version 3.20 only; version 3.21 only
Published 2026-09-30. Last modified 2026-10-01.