Access of Uninitialized Pointer in BIG-IP - CVE-2026-39458
Published: May 14, 2026
BIG-IP
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to access of uninitialized pointer in the BIG-IP DNS profile with DNS cache enabled when handling undisclosed traffic on a virtual server. A remote attacker can send crafted traffic to cause a denial of service.
There is no control plane exposure; this is a data plane issue only.