Impact
Flooding the system with undisclosed HTTP/2 requests when an HTTP/2 profile is active on a virtual server can dramatically increase memory consumption, reducing the performance of the Traffic Management Module until it must be restarted. The resulting degradation can prevent traffic from being processed, effectively causing a denial‑of-service for any services running on the device.
Affected Systems
All F5 BIG‑IP products that support virtual servers with an HTTP/2 profile – including BIG‑IP, BIG‑IP Next CNF, BIG‑IP Next SPK, and BIG‑IP Next for Kubernetes – are impacted. Releases that have reached End‑of‑Technical Support are not evaluated for this issue.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score of less than 1% reflects a very low but non‑zero likelihood of exploitation, and the vulnerability is not listed in CISA KEV. Attackers need only network access to the affected virtual server; no authentication or control‑plane interaction is required. The flaw is confined to the data plane, but the memory exhaustion can bring the BIG‑IP down, posing a significant availability risk.
OpenCVE Enrichment