Executive brief
F5 BIG-IP devices, which manage and secure corporate web traffic, are vulnerable to a flaw that can cause the system to crash. An attacker can send specifically crafted web requests to a server configured with certain redirection rules, leading to a complete service outage. This disrupts network operations and prevents legitimate users from accessing protected applications.
Technical details
This vulnerability is a NULL pointer dereference (CWE-476) within the Traffic Management Microkernel (TMM) of F5 BIG-IP. It occurs when a virtual server is configured with both an HTTP/2 profile and an iRule that utilizes the 'HTTP::redirect' or 'HTTP::respond' commands. An unauthenticated remote attacker can exploit this by sending undisclosed HTTP/2 requests that trigger the flaw during the redirection or response logic, leading to a TMM process termination and a denial-of-service (DoS) condition. The issue affects multiple BIG-IP modules including LTM, APM, and Advanced WAF across versions 16.x and 17.x.
Affected products
- F5 BIG-IP Access Policy Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP Advanced Firewall Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP Local Traffic Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP Advanced WAF 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
Timeline
- 2026-05-13: disclosed: Initial publication of the vulnerability advisory.