CVE-2025-36504: BIG-IP HTTP/2 vulnerability
When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase in memory resource utilization.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36504?
CVE-2025-36504 has not publicly specified its severity level, but it can lead to increased memory resource utilization in affected systems.
How do I fix CVE-2025-36504?
To mitigate CVE-2025-36504, upgrade to the recommended versions of F5 BIG-IP software as per the vendor's advisory.
Which versions of F5 BIG-IP are affected by CVE-2025-36504?
CVE-2025-36504 affects specific versions of F5 BIG-IP, including 20.2.0 to 20.3.0, and a range of versions for BIG-IP Next SPK and CNF.
What impact does CVE-2025-36504 have on my F5 BIG-IP system?
CVE-2025-36504 can cause an increase in memory resource utilization due to undisclosed responses when the HTTP/2 httprouter profile is configured.
Is there a workaround for CVE-2025-36504 if I cannot update my system?
Currently, no specific workaround for CVE-2025-36504 has been publicly disclosed, making an upgrade the recommended response.