8.7

CVE-2026-59762

Medienbericht

BIG-IP HTTP/2 vulnerability

When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.  









Impact:
System performance can degrade until the TMM process is either forced to restart or is manually restarted. This vulnerability allows a remote, unauthenticated attacker to cause a degradation of service that can lead to a denial-of-service (DoS) on the BIG-IP system. There is no control plane exposure; this is a data plane issue only.





Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
F5Big-ip Next Cloud-native Network Functions Version >= 1.1.0 < 1.4.3
F5Big-ip Next Cloud-native Network Functions Version >= 2.0.0 < 2.2.3
F5Big-ip Next For Kubernetes Version >= 2.0.0 < 2.2.3
F5Big-ip Next For Kubernetes Version2.3.0
F5Big-ip Next Service Proxy For Kubernetes Version >= 1.7.0 < 1.7.18
F5Big-ip Next Service Proxy For Kubernetes Version >= 1.8.0 <= 1.9.2
F5Big-ip Next Service Proxy For Kubernetes Version >= 2.0.0 <= 2.0.3
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.374
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
F5 8.7 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
F5 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
20.07.2026 15:58
https://my.f5.com/manage/s/article/K000162231
Vendor Advisory