CVE-2026-59762 Details
Description
When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Impact: System performance can degrade until the TMM process is either forced to restart or is manually restarted. This vulnerability allows a remote, unauthenticated attacker to cause a degradation of service that can lead to a denial-of-service (DoS) on the BIG-IP system. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
A denial-of-service vulnerability has been identified in F5 BIG-IP systems when an HTTP/2 profile is active on a virtual server. Undisclosed requests can cause excessive memory usage, degrading system performance. This issue affects the Traffic Management Microkernel (TMM) process, which may require a manual or forced restart to recover. The vulnerability allows remote, unauthenticated attackers to disrupt service, creating a denial-of-service condition on the affected BIG-IP system.
To address this vulnerability, users can upgrade to a fixed version. For BIG-IP Next SPK, versions 2.0.0 to 2.0.3 are vulnerable, while version 2.3.2 is a fixed version. For BIG-IP Next CNF, versions 2.0.0 to 2.3.1 are vulnerable, with version 2.3.2 available as a fix. In the BIG-IP 21.x branch, versions 21.0.0 to 21.1.0 are vulnerable, while version 21.1.0.1 is a fixed version. For BIG-IP 17.x, versions 17.5.0 to 17.5.1 and 17.1.0 to 17.1.3 are vulnerable, with versions 17.5.1.8 and 17.1.3.4 available as fixes. Users can also create a custom eviction policy with Slow Flow Monitoring enabled and associate it with the affected virtual server as a mitigation strategy.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://my.f5.com/manage/s/article/K000162231 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| f5 big-ip next cloud-native network functions | >= 1.1.0, < 1.4.3 >= 2.0.0, < 2.2.3 2.3.0 |
CPE
Remediation
| |
| f5 big-ip next for kubernetes | >= 2.0.0, < 2.2.3 2.3.0 |
CPE
Remediation
| |
| f5 big-ip next service proxy for kubernetes | >= 1.7.0, < 1.7.18 >= 1.8.0, <= 1.9.2 >= 2.0.0, <= 2.0.3 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 6, 2026 | Initial Analysis | [email protected] |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | New CVE Received | [email protected] |