Junglewise Threat Intelligence

CVE-2026-42409: F5 BIG-IP DoS via HTTP/2 iRule redirection

CVE-2026-42409 · Severity: high · CVSS 7.5 · Published 2026-05-13

Technologies: F5 BIG-IP Advanced WAF, F5 Big-Ip Access Policy Manager, F5 Big-Ip Local Traffic Manager, F5 BIG-IP, F5 Big-Ip Advanced Firewall Manager. Vendors: F5.

Executive brief

F5 BIG-IP devices, which manage and secure corporate web traffic, are vulnerable to a flaw that can cause the system to crash. An attacker can send specifically crafted web requests to a server configured with certain redirection rules, leading to a complete service outage. This disrupts network operations and prevents legitimate users from accessing protected applications.

Technical details

This vulnerability is a NULL pointer dereference (CWE-476) within the Traffic Management Microkernel (TMM) of F5 BIG-IP. It occurs when a virtual server is configured with both an HTTP/2 profile and an iRule that utilizes the 'HTTP::redirect' or 'HTTP::respond' commands. An unauthenticated remote attacker can exploit this by sending undisclosed HTTP/2 requests that trigger the flaw during the redirection or response logic, leading to a TMM process termination and a denial-of-service (DoS) condition. The issue affects multiple BIG-IP modules including LTM, APM, and Advanced WAF across versions 16.x and 17.x.

Affected products

  • F5 BIG-IP Access Policy Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Advanced Firewall Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Local Traffic Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Advanced WAF 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0

Timeline

  • 2026-05-13: disclosed: Initial publication of the vulnerability advisory.

References

Related threats