
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-59762 is a denial-of-service vulnerability in F5 BIG-IP and BIG-IP Next products caused by uncontrolled memory resource consumption when an HTTP/2 profile is configured on a virtual server. Undisclosed requests trigger excessive memory utilization in the Traffic Management Microkernel (TMM) process, degrading system performance until TMM is restarted. Affected products include BIG-IP (versions 17.1.0–17.1.3.4, 17.5.0–17.5.1.8, 21.0.0–21.0.0.3, 21.1.0–21.1.0.1), BIG-IP Next for Kubernetes (2.0.0–2.2.3, 2.3.0–2.3.2), BIG-IP Next SPK (1.7.0–1.7.18, 1.9.0+), and BIG-IP Next CNF (1.1.0–1.4.3, 2.0.0–2.2.3, 2.3.0–2.3.2). The vulnerability was published on July 15, 2026, and carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, F5 Advisory).
The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), where the BIG-IP HTTP/2 processing code fails to impose adequate restrictions on memory allocation when handling certain undisclosed request patterns. An unauthenticated, remote attacker can send specially crafted HTTP/2 requests to a virtual server with an HTTP/2 profile enabled, causing the TMM process to progressively consume memory without releasing it. This is a data plane issue only — the control plane is not exposed, meaning administrative interfaces are not directly at risk. No authentication or user interaction is required, and the attack can be automated, making it particularly accessible to threat actors (GitHub Advisory, F5 Advisory).
Successful exploitation causes progressive memory exhaustion in the TMM process, leading to degraded system performance and ultimately a denial-of-service condition on the BIG-IP system. The impact is limited to availability — there is no confidentiality or integrity impact, and no lateral movement or data exfiltration risk is associated with this vulnerability. Service disruption persists until the TMM process is forcibly or manually restarted, potentially causing extended outages for traffic passing through affected virtual servers (GitHub Advisory, F5 Advisory).
No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at the time of publication. The EPSS score is approximately 0.33–0.46%, indicating a low near-term exploitation probability. The attack is classified as automatable (no user interaction required), which lowers the barrier for opportunistic exploitation. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog as of the available data (GitHub Advisory, F5 Advisory).
curl --http2 or nghttp).tmsh show sys performance commands; system alerts or SNMP traps related to memory thresholds being exceeded./var/log/ltm) showing TMM memory warnings or OOM-related messages; logs indicating TMM process restarts or crashes correlated with inbound HTTP/2 traffic spikes.F5 has released patched versions addressing this vulnerability: BIG-IP 17.1.3.4, 17.5.1.8, 21.0.0.3, and 21.1.0.1; BIG-IP Next for Kubernetes 2.2.3 and 2.3.2; BIG-IP Next SPK 1.7.18; and BIG-IP Next CNF 1.4.3, 2.2.3, and 2.3.2. As a workaround prior to patching, administrators should consider removing or restricting HTTP/2 profiles from virtual servers where not strictly required, implementing network-level rate limiting or request filtering for HTTP/2 connections, and monitoring TMM memory utilization closely. Upgrading to a patched version is the recommended long-term remediation (F5 Advisory, GitHub Advisory).
The vulnerability received coverage from multiple cybersecurity news outlets including CyberSecurityNews and SecurityOnline, with articles highlighting the memory exhaustion risk to BIG-IP deployments (CyberSecurityNews). Field Effect and The Hacker News included it in weekly security roundups, indicating moderate industry attention (Field Effect Blog, The Hacker News). A Reddit thread in r/sysadmin discussed the vulnerability, reflecting practitioner-level awareness among BIG-IP administrators. CISA included it in its weekly vulnerability bulletin (SB26-201), signaling relevance to government and critical infrastructure operators (CISA Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."