8.7
CVE-2026-59762
- EPSS 0.46%
- Veröffentlicht 15.07.2026 14:33:44
- Zuletzt bearbeitet 06.08.2026 18:20:20
- CVE-Watchlists
- Unerledigt
BIG-IP HTTP/2 vulnerability
When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Impact: System performance can degrade until the TMM process is either forced to restart or is manually restarted. This vulnerability allows a remote, unauthenticated attacker to cause a degradation of service that can lead to a denial-of-service (DoS) on the BIG-IP system. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
F5 ≫ Big-ip Next Cloud-native Network Functions Version >= 1.1.0 < 1.4.3
F5 ≫ Big-ip Next Cloud-native Network Functions Version >= 2.0.0 < 2.2.3
F5 ≫ Big-ip Next Cloud-native Network Functions Version2.3.0
F5 ≫ Big-ip Next For Kubernetes Version >= 2.0.0 < 2.2.3
F5 ≫ Big-ip Next For Kubernetes Version2.3.0
F5 ≫ Big-ip Next Service Proxy For Kubernetes Version >= 1.7.0 < 1.7.18
F5 ≫ Big-ip Next Service Proxy For Kubernetes Version >= 1.8.0 <= 1.9.2
F5 ≫ Big-ip Next Service Proxy For Kubernetes Version >= 2.0.0 <= 2.0.3
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.46% | 0.374 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| F5 | 8.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| F5 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-770 Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://my.f5.com/manage/s/article/K000162231