Junglewise Threat Intelligence

CVE-2026-34019: F5 BIG-IP denial of service in BFD routing protocols

CVE-2026-34019 · Severity: medium · CVSS 5.3 · Published 2026-05-13

Technologies: F5 Big-Ip Access Policy Manager, F5 Big-Ip Local Traffic Manager, F5 BIG-IP, F5 Big-Ip Advanced Firewall Manager. Vendors: F5.

Executive brief

F5 BIG-IP devices, which manage and secure enterprise network traffic, are vulnerable to a denial-of-service issue when using certain routing protocols. An attacker can send specific network traffic that causes the device to stop processing health-check signals, leading to an unexpected network failover. This can result in temporary service disruptions or instability in how the network routes user traffic.

Technical details

A vulnerability exists in the F5 BIG-IP Traffic Management Microkernel (TMM) related to the handling of Bidirectional Forwarding Detection (BFD) packets. When BFD is enabled for static or dynamic routing protocols, undisclosed network traffic can trigger a condition where TMM stops processing BFD packets. This leads to a timeout in the BFD session, causing the associated routing protocols to incorrectly assume a link failure and initiate a failover. The vulnerability is classified as CWE-410 (Insufficient Resource Pool) and can be exploited by a remote, unauthenticated attacker. Fixed versions include 17.5.1 and 17.1.2-ENG, while version 21.0.0 is reported as unaffected.

Affected products

  • F5 BIG-IP Access Policy Manager 16.1.0 - 16.1.6, 17.1.0 - 17.1.2, 17.5.0
  • F5 BIG-IP Advanced Firewall Manager 16.1.0 - 16.1.6, 17.1.0 - 17.1.2, 17.5.0
  • F5 BIG-IP Local Traffic Manager 16.1.0 - 16.1.6, 17.1.0 - 17.1.2, 17.5.0
  • F5 BIG-IP Global Traffic Manager 16.1.0 - 16.1.6, 17.1.0 - 17.1.2, 17.5.0

Timeline

  • 2026-05-13: disclosed
  • 2026-05-13: advisory

References

Related threats