
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-59762 is a denial-of-service vulnerability in F5 BIG-IP and BIG-IP Next products caused by uncontrolled memory resource consumption when an HTTP/2 profile is configured on a virtual server. Undisclosed requests trigger excessive memory utilization in the Traffic Management Microkernel (TMM) process, degrading system performance until TMM is restarted. Affected products include BIG-IP (versions 17.1.0–17.1.3.4, 17.5.0–17.5.1.8, 21.0.0–21.0.0.3, 21.1.0–21.1.0.1), BIG-IP Next for Kubernetes (2.0.0–2.2.3, 2.3.0–2.3.2), BIG-IP Next SPK (1.7.0–1.7.18, 1.9.0+), and BIG-IP Next CNF (1.1.0–1.4.3, 2.0.0–2.2.3, 2.3.0–2.3.2). The vulnerability was published on July 15, 2026, and carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, F5 Advisory).
The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), where the BIG-IP TMM process fails to impose adequate restrictions on memory allocation when processing certain HTTP/2 requests. An unauthenticated remote attacker can send specially crafted HTTP/2 requests to a virtual server with an HTTP/2 profile enabled, causing progressive memory exhaustion. The vulnerability is a data plane issue only — there is no control plane exposure, meaning management interfaces are not directly affected. No public proof-of-concept code has been identified at this time (GitHub Advisory, F5 Advisory).
Successful exploitation causes progressive memory resource exhaustion in the TMM process, leading to degraded system performance and ultimately a denial-of-service condition on the BIG-IP system. The impact is limited to availability — there is no confidentiality or integrity impact, and no lateral movement or data exposure risk is associated with this vulnerability. Service disruption persists until the TMM process is either forced to restart automatically or manually restarted by an administrator, potentially causing significant downtime for traffic managed by the affected virtual servers (GitHub Advisory, F5 Advisory).
tmsh show sys performance commands./var/log/ltm) showing TMM memory warnings, OOM (out-of-memory) events, or unexpected TMM process restarts./var/log/tmm or /var/log/daemon.log.F5 has released patched versions addressing this vulnerability: BIG-IP 17.1.3.4, 17.5.1.8, 21.0.0.3, and 21.1.0.1; BIG-IP Next for Kubernetes 2.2.3 and 2.3.2; BIG-IP Next SPK 1.7.18; and BIG-IP Next CNF 1.4.3, 2.2.3, and 2.3.2. As interim mitigations, administrators should configure network-level rate limiting or request filtering for HTTP/2 connections, monitor TMM memory utilization closely, and consider restricting HTTP/2 profile usage to only necessary virtual servers. Upgrading to a patched version is the recommended long-term remediation (F5 Advisory, GitHub Advisory).
The vulnerability received community attention on Reddit's r/sysadmin shortly after disclosure, with administrators discussing impact assessment and patching timelines. Field Effect published a blog post covering F5 updates including this CVE, and The Hacker News included it in a weekly security recap. CISA referenced the vulnerability in its security bulletin SB26-201. No significant researcher controversy or vendor dispute has been noted (Field Effect Blog, The Hacker News, CISA Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."