F5 BIG-IP HTTP/2 TMM memory exhaustion (CVE-2026-59762)
F5 CNA advisory K000162231 (NVD published 15 July 2026) says that when an HTTP/2 profile is configured on a virtual server, undisclosed requests can raise TMM memory until the process restarts. That is a data-plane denial of service; F5 says there is no control-plane exposure. F5 scores it 8.7 (CVSS 4.0) and 7.5 (CVSS 3.1). Affected classic BIG-IP: 21.1.0 before 21.1.0.1, 21.0.0 before 21.0.0.3, 17.5.0 before 17.5.1.8, 17.1.0 before 17.1.3.4. Also BIG-IP Next for Kubernetes 2.3 before 2.3.2 and 2.0 before 2.2.3, Next CNF 2.3 before 2.3.2 / 2.0 before 2.2.3 / 1.1 before 1.4.3, and Next SPK 1.7 before 1.7.18 (NVD also lists Next SPK 1.9.0 as affected with no upper bound). Not in CISA KEV at last check. The NVD record does not state in-the-wild exploitation.
- Product
- F5 BIG-IP (all modules); BIG-IP Next for Kubernetes / SPK / CNF (TMM)
- Versions
- BIG-IP 21.1.0 before 21.1.0.1; 21.0.0 before 21.0.0.3; 17.5.0 before 17.5.1.8; 17.1.0 before 17.1.3.4; Next Kubernetes/CNF 2.3 before 2.3.2 and 2.0 before 2.2.3; Next CNF 1.1 before 1.4.3; Next SPK 1.7 before 1.7.18 (1.9.0 listed affected)
- CVSS
- (CVSS 4.0, F5); 7.5 (CVSS 3.1, F5)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N - Exploited in Australia?
- unknown
- Patch to
- 21.1.0.1; 21.0.0.3; 17.5.1.8; 17.1.3.4; Next Kubernetes/CNF 2.3.2 or 2.2.3; Next CNF 1.4.3; Next SPK 1.7.18 (see K000162231 for your branch)
Primary: F5 K000162231 · Vendor: F5 SIRT · CVE: CVE-2026-59762 · NVD CVE-2026-59762
