Allocation of Resources Without Limits or Throttling in F5 Networks products - CVE-2026-59762
Published: July 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in TMM when processing undisclosed HTTP/2 requests on a virtual server with an HTTP/2 profile configured. A remote attacker can send crafted requests to cause a denial of service.
There is no control plane exposure; this issue affects the data plane only.
Affected software
BIG-IP Next SPK
BIG-IP Next for Kubernetes
BIG-IP
How to mitigate CVE-2026-59762
BIG-IP Next SPK - update to 1.7.18
BIG-IP Next for Kubernetes - addressed in versions 2.2.3, 2.3.2
BIG-IP - addressed in versions 17.1.3.4, 17.5.1.8, 21.0.0.3, 21.1.0.1