CVE-2026-57054
A Use of Incorrectly-Resolved Name or Reference vulnerability in the URL filtering plugin of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass web filtering and access downstream resources that should be unreachable. If an MX Series device is configured with web filtering, and an attacker sends a request with a specifically formatted URL, this request will get forwarded despite the system being configured to block it. In turn, an attacker can access downstream resources that are expected to be unreachable. This issue affects Junos OS on MX Series: * all versions before 23.2R2-S7, * 23.4 versions before 23.4R2-S8, * 24.2 versions before 24.2R2-S5, * 24.4 versions before 24.4R2-S4, * 25.2 versions before 25.2R2-S1, * 25.4 versions before 25.4R1-S2, 25.4R2.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/AU:Y/RE:M
- EPSS probability
- 0.37%
- CWE
- CWE-706
- Published
- 2026-07-09
- Last modified
- 2026-07-10
Affected products
- Juniper Networks Junos OS
- Juniper Networks Junos OS
- Juniper Networks Junos OS
- Juniper Networks Junos OS
- Juniper Networks Junos OS
- Juniper Networks Junos OS
Weakness type
Related vulnerabilities
- CVE-2026-87618 — Incorrect reference resolution in Storage in Google Chrome on on Windows prior to 153.0.8010.36...
- CVE-2026-87562 — Incorrect reference resolution in Accessibility in Google Chrome on on Mac prior to 153.0.8010.36...
- CVE-2026-87613 — Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a...
- CVE-2026-87547 — Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a...
- CVE-2026-81383 — Visual Studio Code Information Disclosure Vulnerability
- CVE-2026-79254 — Incorrect reference resolution in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65...
- CVE-2026-79273 — Incorrect reference resolution in WebView in Google Chrome on on Android prior to 152.0.7977.65...
- CVE-2026-79103 — Incorrect reference resolution in Speech in Google Chrome prior to 152.0.7977.65 allowed a remote...