CVE-2025-46706: BIG-IP iRules vulnerability
When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46706?
CVE-2025-46706 is classified as a high-severity vulnerability due to its impact on memory resource utilization.
How do I fix CVE-2025-46706?
To fix CVE-2025-46706, upgrade your F5 BIG-IP software to the recommended remedial version as specified in the advisory.
Which products are affected by CVE-2025-46706?
CVE-2025-46706 affects various F5 products, including BIG-IP Next SPK, BIG-IP Next CNF, BIG-IP Next for Kubernetes, and different versions of BIG-IP.
What is the risk of not addressing CVE-2025-46706?
Not addressing CVE-2025-46706 may lead to increased memory resource utilization, potentially causing performance degradation and system instability.
What specific versions of F5 products are vulnerable to CVE-2025-46706?
CVE-2025-46706 specifically affects F5 products running certain versions of BIG-IP and BIG-IP Next variants as specified in the vulnerability advisory.