#VU108775 Resource exhaustion in F5 Networks products - CVE-2025-36504
Published: May 7, 2025
BIG-IP
BIG-IP Next SPK
BIG-IP Next CNF
F5 Networks
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to system does not properly control consumption of internal resources when BIG-IP HTTP/2 httprouter profile is configured on a virtual server. A remote attacker can send specially crafted HTTP2 requests to the system and perform a denial of service (DoS) attack.