Description

When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Impact: System performance can degrade until the TMM process is either forced to restart or is manually restarted. This vulnerability allows a remote, unauthenticated attacker to cause a degradation of service that can lead to a denial-of-service (DoS) on the BIG-IP system. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Severity (CVSS)

Base score8.7
SeverityHigh
VersionCVSS 4.0
VectorCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Provided byCNA

Weaknesses

  • CWE-770 — CWE-770: Allocation of Resources Without Limits or Throttling

Affected products

VendorProductVersions
F5BIG-IP21.1.0 to <21.1.0.1; 21.0.0 to <21.0.0.3; 17.5.0 to <17.5.1.8; 17.1.0 to <17.1.3.4
F5BIG-IP Next for Kubernetes2.3.0 to <2.3.2; 2.0.0 to <2.2.3
F5BIG-IP Next SPK1.9.0 to <*; 1.7.0 to <1.7.18
F5BIG-IP Next CNF2.3.0 to <2.3.2; 2.0.0 to <2.2.3; 1.1.0 to <1.4.3

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 16 Jul 2026 07:01 UTC.