PT-2026-60185 · F5 · Big-Ip
CVE-2026-59762
·
Published
2026-07-15
·
Updated
2026-08-06
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
F5 BIG-IP (affected versions not specified)
Description
When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. This allows a remote, unauthenticated attacker to cause a degradation of service that can lead to a denial-of-service (DoS) on the system. The issue specifically affects the data plane, potentially degrading system performance until the TMM (Traffic Management Microkernel) process is either forced to restart or is manually restarted.
Recommendations
Upgrade to a vendor-listed fixed release.
As a temporary mitigation, consider disabling the HTTP/2 profile on virtual servers to minimize the risk of exploitation.
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Big-Ip