Junglewise Threat Intelligence

CVE-2026-42920: F5 BIG-IP DoS in TMM via Client SSL Dynamic Record Sizing

CVE-2026-42920 · Severity: high · CVSS 7.5 · Published 2026-05-13

Executive brief

F5 BIG-IP networking devices are susceptible to a denial-of-service vulnerability when processing specific types of encrypted traffic. An attacker can send specially crafted network data to a virtual server, causing the core traffic management component to crash. This results in a complete interruption of network services and application delivery managed by the affected device.

Technical details

A vulnerability classified as an infinite loop (CWE-835) exists in the F5 BIG-IP Traffic Management Microkernel (TMM). The issue is triggered when a Client SSL profile is configured with 'Allow Dynamic Record Sizing' on a UDP-based virtual server. An unauthenticated remote attacker can send undisclosed network traffic that causes TMM to terminate, leading to a denial-of-service (DoS) condition. The vulnerability affects multiple BIG-IP modules including LTM, APM, AFM, and ASM across versions 16.1.x, 17.5.x, and 21.0.0. F5 has provided mitigation guidance in advisory K000160901.

Affected products

  • F5 BIG-IP Access Policy Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Advanced Firewall Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Local Traffic Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
  • F5 BIG-IP Application Security Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0

Timeline

  • 2026-05-13: advisory: Initial publication of the vulnerability advisory

References

Related threats