Junglewise Threat Intelligence

CVE-2026-59762: F5 BIG-IP denial of service in HTTP/2 profile memory management

CVE-2026-59762 · Severity: high · CVSS 7.5 · Published 2026-07-15

Executive brief

F5 BIG-IP networking devices are susceptible to a denial-of-service vulnerability when processing specific web traffic. An attacker can send specially crafted requests that consume excessive system memory, eventually causing the device to slow down or crash. This can disrupt network availability and prevent legitimate users from accessing services protected by the BIG-IP system.

Technical details

A resource exhaustion vulnerability (CWE-770) exists in the F5 BIG-IP Traffic Management Microkernel (TMM) when an HTTP/2 profile is configured on a virtual server. Remote, unauthenticated attackers can send undisclosed HTTP/2 requests that trigger an unintended increase in memory resource utilization. This memory leak or excessive allocation eventually leads to performance degradation and a DoS condition when the TMM process either crashes or requires a manual restart. The vulnerability is limited to the data plane and does not expose the control plane. Patch information is available in F5 advisory K000162231.

Affected products

  • F5 BIG-IP 21.1.0 to 21.1.0.1, 21.0.0 to 21.0.0.3, 17.5.0 to 17.5.1.8, 17.1.0 to 17.1.3.4
  • F5 BIG-IP Next for Kubernetes 2.3.0 to 2.3.2, 2.0.0 to 2.2.3
  • F5 BIG-IP Next SPK 1.9.0, 1.7.0 to 1.7.18
  • F5 BIG-IP Next CNF 2.3.0 to 2.3.2, 2.0.0 to 2.2.3, 1.1.0 to 1.4.3

Timeline

  • 2026-07-15: advisory: Initial publication by F5 Networks

References

Related threats