๐Ÿ” CVE Alert

CVE-2026-102253

HIGH 7.5

iperf3 < 3.22 UDP Receive Worker Infinite Loop DoS

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the server's UDP receive worker into an unrecoverable infinite loop by sending a single crafted control-channel parameter message followed by one 16-byte UDP datagram. Attackers can permanently pin the affected per-stream receive thread at approximately 100% CPU usage, rendering the server unusable until forcibly killed with SIGKILL, as the process does not respond to normal control-channel closure.

CWE CWE-835
Vendor esnet
Product iperf3
Published Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for esnet iperf3

Be the first to know when new high vulnerabilities affecting esnet iperf3 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

esnet / iperf3
3.14 < 3.22

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/esnet/iperf/releases/tag/3.22 github.com: https://github.com/esnet/iperf/blob/master/RELNOTES.md vulncheck.com: https://www.vulncheck.com/advisories/iperf3-udp-receive-worker-infinite-loop-dos

Credits

Ravindu Lakmina Munaweera VulnCheck