Allocation of Resources Without Limits or Throttling in BIG-IP - CVE-2026-40423
Published: May 14, 2026
BIG-IP
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the SIP profile on a virtual server when processing traffic. A remote attacker can send undisclosed traffic to cause a denial of service.
There is no control plane exposure; this is a data plane issue only.