CVE-2025-46706 Details
Description
When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A vulnerability exists in F5 BIG-IP when an iRule using the HTTP::respond command is applied to a virtual server. Undisclosed requests can trigger increased memory usage, causing system performance to degrade. This issue can lead to a denial-of-service condition on the BIG-IP system by causing the Traffic Management Microkernel (TMM) process to crash or requiring a manual restart. The vulnerability affects BIG-IP versions 17.1.0 through 17.1.2, 16.1.0 through 16.1.5, and certain 1.x releases of BIG-IP Next SPK, BIG-IP Next CNF, and BIG-IP Next for Kubernetes.
To address this vulnerability, users can upgrade to BIG-IP versions 17.5.0 or 17.1.2.2, or to BIG-IP Next versions 1.4.0-EHF-3. For those using BIG-IP Next SPK, the vulnerability can be mitigated by adding a 'Connection close' header to the affected iRules. This can be done by modifying the iRule to include 'Connection close' at the end of the 'HTTP::respond' command.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://my.f5.com/manage/s/article/K000151611 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| f5 big-ip next cloud-native network functions | >= 1.1.0, <= 1.4.1 |
CPE
Remediation
| |
| f5 big-ip next service proxy for kubernetes | >= 1.7.0, <= 1.9.2 |
CPE
Remediation
| |
| f5 big-ip access policy manager | >= 16.1.0, < 16.1.6 >= 17.1.0, < 17.1.2.2 |
CPE
Remediation
| |
| f5 big-ip advanced firewall manager | >= 16.1.0, < 16.1.6 >= 17.1.0, < 17.1.2.2 |
CPE
Remediation
| |
| f5 big-ip advanced web application firewall | >= 16.1.0, < 16.1.6 >= 17.1.0, < 17.1.2.2 |
CPE
Remediation
| |
| f5 big-ip analytics | >= 16.1.0, < 16.1.6 >= 17.1.0, < 17.1.2.2 |
CPE
Remediation
| |
| f5 big-ip application acceleration manager | >= 16.1.0, < 16.1.6 >= 17.1.0, < 17.1.2.2 |
CPE
Remediation
| |
| f5 big-ip application security manager | >= 16.1.0, < 16.1.6 >= 17.1.0, < 17.1.2.2 |
CPE
Remediation
| |
| f5 big-ip application visibility and reporting | >= 16.1.0, < 16.1.6 >= 17.1.0, < 17.1.2.2 |
CPE
Remediation
| |
| f5 big-ip automation toolchain | >= 16.1.0, < 16.1.6 >= 17.1.0, < 17.1.2.2 |
CPE
Remediation
| |
| f5 big-ip carrier-grade nat | >= 16.1.0, < 16.1.6 >= 17.1.0, < 17.1.2.2 |
CPE
Remediation
| |
| f5 big-ip container ingress services | >= 16.1.0, < 16.1.6 >= 17.1.0, < 17.1.2.2 |
CPE
Remediation
| |
| f5 big-ip ddos hybrid defender | >= 16.1.0, < 16.1.6 >= 17.1.0, < 17.1.2.2 |
CPE
Remediation
| |
| f5 big-ip domain name system | >= 16.1.0, < 16.1.6 >= 17.1.0, < 17.1.2.2 |
CPE
Remediation
| |
| f5 big-ip edge gateway | >= 16.1.0, < 16.1.6 >= 17.1.0, < 17.1.2.2 |
CPE
Remediation
| |
| f5 big-ip fraud protection service | >= 16.1.0, < 16.1.6 >= 17.1.0, < 17.1.2.2 |
CPE
Remediation
| |
| f5 big-ip global traffic manager | >= 16.1.0, < 16.1.6 >= 17.1.0, < 17.1.2.2 |
CPE
Remediation
| |
| f5 big-ip link controller | >= 16.1.0, < 16.1.6 >= 17.1.0, < 17.1.2.2 |
CPE
Remediation
| |
| f5 big-ip local traffic manager | >= 16.1.0, < 16.1.6 >= 17.1.0, < 17.1.2.2 |
CPE
Remediation
| |
| f5 big-ip policy enforcement manager | >= 16.1.0, < 16.1.6 >= 17.1.0, < 17.1.2.2 |
CPE
Remediation
| |
| f5 big-ip ssl orchestrator | >= 16.1.0, < 16.1.6 >= 17.1.0, < 17.1.2.2 |
CPE
Remediation
| |
| f5 big-ip webaccelerator | >= 16.1.0, < 16.1.6 >= 17.1.0, < 17.1.2.2 |
CPE
Remediation
| |
| f5 big-ip websafe | >= 16.1.0, < 16.1.6 >= 17.1.0, < 17.1.2.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | Initial Analysis | [email protected] |
| Oct 15, 2025 | New CVE Received | [email protected] |