{"id":"JLSEC-2026-762","details":"In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.","modified":"2026-07-18T00:02:23.029931538Z","published":"2026-07-15T15:02:37.321Z","upstream":["CVE-2025-54349"],"database_specific":{"license":"CC-BY-4.0","sources":[{"id":"CVE-2025-54349","imported":"2026-07-17T22:38:02.169Z","modified":"2026-06-17T09:39:54.910Z","published":"2025-08-03T02:15:35.597Z","url":"https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-54349","html_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54349","database_specific":{"status":"Modified"}}]},"references":[{"type":"WEB","url":"https://github.com/esnet/iperf/commit/4e5313bab0b9b3fe03513ab54f722c8a3e4b7bdf"},{"type":"WEB","url":"https://github.com/esnet/iperf/releases/tag/3.19.1"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/08/msg00020.html"}],"affected":[{"package":{"name":"iperf_jll","ecosystem":"Julia","purl":"pkg:julia/iperf_jll?uuid=c3111fcb-6a66-54cb-a6df-fd652d9c82a2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.21.0+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-762.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}