Description
When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.  









Impact:
System performance can degrade until the TMM process is either forced to restart or is manually restarted. This vulnerability allows a remote, unauthenticated attacker to cause a degradation of service that can lead to a denial-of-service (DoS) on the BIG-IP system. There is no control plane exposure; this is a data plane issue only.





Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published: 2026-07-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Flooding the system with undisclosed HTTP/2 requests when an HTTP/2 profile is active on a virtual server can dramatically increase memory consumption, reducing the performance of the Traffic Management Module until it must be restarted. The resulting degradation can prevent traffic from being processed, effectively causing a denial‑of-service for any services running on the device.

Affected Systems

All F5 BIG‑IP products that support virtual servers with an HTTP/2 profile – including BIG‑IP, BIG‑IP Next CNF, BIG‑IP Next SPK, and BIG‑IP Next for Kubernetes – are impacted. Releases that have reached End‑of‑Technical Support are not evaluated for this issue.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score of less than 1% reflects a very low but non‑zero likelihood of exploitation, and the vulnerability is not listed in CISA KEV. Attackers need only network access to the affected virtual server; no authentication or control‑plane interaction is required. The flaw is confined to the data plane, but the memory exhaustion can bring the BIG‑IP down, posing a significant availability risk.

Generated by OpenCVE AI on July 31, 2026 at 03:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑released fix that addresses the HTTP/2 memory‑exhaustion problem.
  • Disable the HTTP/2 profile on virtual servers that do not require it until a patch is available.
  • Restrict inbound traffic to the virtual servers via network segmentation or IP filtering to limit exposure to malicious requests.
  • Monitor the memory usage of the TMM process and schedule or trigger a restart when usage becomes abnormal or the module stops responding.

Generated by OpenCVE AI on July 31, 2026 at 03:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared F5
F5 big-ip
F5 big-ip Next Cnf
F5 big-ip Next For Kubernetes
F5 big-ip Next Spk
Vendors & Products F5
F5 big-ip
F5 big-ip Next Cnf
F5 big-ip Next For Kubernetes
F5 big-ip Next Spk

Wed, 15 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.   Impact: System performance can degrade until the TMM process is either forced to restart or is manually restarted. This vulnerability allows a remote, unauthenticated attacker to cause a degradation of service that can lead to a denial-of-service (DoS) on the BIG-IP system. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Title BIG-IP HTTP/2 vulnerability
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

F5 Big-ip Big-ip Next Cnf Big-ip Next For Kubernetes Big-ip Next Spk
cve-icon MITRE

Status: PUBLISHED

Assigner: f5

Published:

Updated: 2026-07-15T15:35:16.895Z

Reserved: 2026-07-08T15:49:43.031Z

Link: CVE-2026-59762

cve-icon Vulnrichment

Updated: 2026-07-15T15:35:08.307Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:45:04Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling