CVE-2026-101276
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a freed iperf_stream; fixed in 3.22.
| CWE | CWE-416 |
| Vendor | esnet |
| Product | iperf3 |
| Published | Sep 30, 2026 |
| Last Updated | Sep 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for esnet iperf3
Be the first to know when new unknown vulnerabilities affecting esnet iperf3 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
esnet / iperf3
3.21
References
Credits
Anthropic ๐ Ada Logics