Resource exhaustion in F5 Networks products - CVE-2025-36504
Published: May 7, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to system does not properly control consumption of internal resources when BIG-IP HTTP/2 httprouter profile is configured on a virtual server. A remote attacker can send specially crafted HTTP2 requests to the system and perform a denial of service (DoS) attack.
Affected software
BIG-IP Next SPK
BIG-IP
How to mitigate CVE-2025-36504
BIG-IP Next SPK - update to 2.0.0
BIG-IP - addressed in versions 16.1.6, 17.1.2, 20.3.0