CVE-2026-101283 PUBLISHED

Assigner: Anthropic
Reserved: 28.09.2026 Published: 30.09.2026 Updated: 01.10.2026

iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.2

Product Status

Vendor esnet
Product iperf3
Versions Default: unaffected
  • Version 3.20 is affected
  • Version 3.21 is affected

Credits

  • Anthropic finder
  • Ada Logics analyst

References

Problem Types

  • CWE-122 Heap-based buffer overflow CWE

Impacts

  • CAPEC-100 Overflow Buffers