CVE-2026-59762: BIG-IP HTTP/2 vulnerability
When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.
Impact: System performance can degrade until the TMM process is either forced to restart or is manually restarted. This vulnerability allows a remote, unauthenticated attacker to cause a degradation of service that can lead to a denial-of-service (DoS) on the BIG-IP system. There is no control plane exposure; this is a data plane issue only.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59762?
The severity of CVE-2026-59762 is high, rated at 7.5.
How does CVE-2026-59762 affect F5 BIG-IP systems?
CVE-2026-59762 can lead to increased memory resource utilization, potentially degrading system performance.
What type of requests can trigger the vulnerability in CVE-2026-59762?
Undisclosed HTTP/2 requests can trigger the vulnerability when configured on a virtual server.
Can CVE-2026-59762 be exploited by unauthenticated users?
Yes, CVE-2026-59762 allows a remote, unauthenticated user to exploit the vulnerability.
What is the recommended action to mitigate CVE-2026-59762?
To mitigate CVE-2026-59762, you should monitor memory usage and consider restarting the TMM process if it becomes unresponsive.