{"id":"AZL-95598","summary":"CVE-2026-71218 affecting package iperf3 3.17.1-4","details":"A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the attacker to trigger excessive memory consumption, leading to a Denial of Service (DoS) through memory exhaustion, severe slowdown, or termination of the iperf3 service.","modified":"2026-08-31T05:26:27Z","published":"2026-08-11T09:17:14Z","upstream":["CVE-2026-71218"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71218"}],"affected":[{"package":{"name":"iperf3","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/iperf3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.17.1-4"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95598.json"}}],"schema_version":"1.9.0"}