Junglewise Threat Intelligence

CVE-2026-42781: F5 BIG-IP resource exhaustion in ePVA acceleration

CVE-2026-42781 · Severity: medium · CVSS 6.5 · Published 2026-05-13

Technologies: F5 BIG-IP. Vendors: F5.

Executive brief

A vulnerability in F5 BIG-IP networking appliances can allow local network traffic to overwhelm the system's processing resources. This occurs when a specific hardware acceleration feature is enabled, potentially leading to a significant slowdown or total service outage. This impact can disrupt corporate network traffic management and application delivery services.

Technical details

A resource exhaustion vulnerability exists in F5 BIG-IP systems when embedded Packet Velocity Acceleration (ePVA) is configured. The flaw is triggered by undisclosed local ethernet traffic, which causes an infinite loop (CWE-835) or similar condition leading to increased resource utilization in both the ePVA hardware and the Traffic Management Microkernel (TMM). An attacker on the adjacent network can exploit this to cause a denial-of-service (DoS) condition. The issue affects multiple BIG-IP modules across rSeries and VELOS platforms. Patches are available in updated versions (e.g., 17.1.3.1, 17.5.1.4, and 21.1.0).

Affected products

  • F5 BIG-IP 17.1.0 to 17.1.3.1, 17.5.0 to 17.5.1.4, 21.0.0 to 21.0.0.1

Timeline

  • 2026-05-13: advisory: Initial advisory published by F5

References

Related threats