CVE-2026-19655: Arista Networks Eos

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with match criteria based on the information option, an unauthenticated attacker connected to a client-facing VLAN(s) where the relay is configured can send a specially crafted packet that causes the DHCP Relay service to restart.

Affected products

  • Arista Networks Eos: from 4.35.0, up to and including 4.35.5M; from 4.34.0, up to and including 4.34.7.1M; from 4.33.0, up to and including 4.33.9M

Published 2026-09-15. Last modified 2026-09-16.