CVE-2025-59778: VELOS partition container network vulnerability
When the Allowed IP Addresses feature is configured on the F5OS-C partition control plane, undisclosed traffic can cause multiple containers to terminate.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Other sources
When the Allowed IP Addresses feature is configured with All for the Port setting in the F5OS-C partition control plane, undisclosed traffic can cause multiple containers to terminate. This issue only affects the F5OS-C partitions; the F5OS-C controller layer is not affected.
— F5
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59778?
CVE-2025-59778 has a severity level that indicates it can lead to the termination of multiple containers.
How do I fix CVE-2025-59778?
To remediate CVE-2025-59778, you should adjust the Allowed IP Addresses feature settings in F5OS-C.
Which versions of F5OS-C are affected by CVE-2025-59778?
CVE-2025-59778 affects F5OS-C versions between 1.6.0 to 1.6.2 and 1.8.0 to 1.8.1.
What causes the issue in CVE-2025-59778?
CVE-2025-59778 is caused by undisclosed traffic interacting with an improperly configured Allowed IP Addresses feature.
Is the F5OS-C controller layer affected by CVE-2025-59778?
No, the F5OS-C controller layer is not affected by CVE-2025-59778.