HIGH
BIG-IP HTTP/2 vulnerability
Published May 13, 2026
8.7
HIGHCVSS 4.0
EPSS 0.46%
Description
When an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected products
-
- Version 16.1.0StatusaffectedConstraints<*
- Version 17.1.0StatusaffectedConstraints<17.1.3.1
- Version 17.5.0StatusaffectedConstraints<17.5.1.4
- Version 21.0.0StatusaffectedConstraints<21.0.0.1
- Version 21.1.0StatusunaffectedConstraints<*
- Version
-
- Version 1.4.0StatusaffectedConstraints<1.4.1
- Version 2.0.0StatusaffectedConstraints<2.0.3
- Version
-
- Version 1.7.0StatusaffectedConstraints<1.7.17
- Version 2.0.0StatusaffectedConstraints<2.0.3
- Version
-
- Version 2.0.0StatusaffectedConstraints<2.1.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| F5 | Big-IP | n/a |
| ||||||||||||||||||
| F5 | BIG-IP Next CNF | n/a |
| ||||||||||||||||||
| F5 | BIG-IP Next SPK | n/a |
| ||||||||||||||||||
| F5 | BIG-IP Next for Kubernetes | n/a |
|
Configuration 1
OR
- ≥ 1.1.0 · ≤ 1.4.0
- ≥ 2.0.0 · ≤ 2.0.2
Configuration 2
- ≥ 2.0.0 · ≤ 2.1.0
Configuration 3
OR
- 21.0.0
- 21.0.0
- 21.0.0
- 21.0.0
- 21.0.0
- 21.0.0
- 21.0.0
- 21.0.0
- 21.0.0
- 21.0.0
- 21.0.0
- 21.0.0
- 21.0.0
- 21.0.0
- 21.0.0
- 21.0.0
- 21.0.0
- 21.0.0
- 21.0.0
- 21.0.0
- 21.0.0
Configuration 4
OR
- ≥ 16.1.0 · ≤ 16.1.6
- ≥ 16.1.0 · ≤ 16.1.6
- ≥ 16.1.0 · ≤ 16.1.6
- ≥ 16.1.0 · ≤ 16.1.6
- ≥ 16.1.0 · ≤ 16.1.6
- ≥ 16.1.0 · ≤ 16.1.6
- ≥ 16.1.0 · ≤ 16.1.6
- ≥ 16.1.0 · ≤ 16.1.6
- ≥ 16.1.0 · ≤ 16.1.6
- ≥ 16.1.0 · ≤ 16.1.6
- ≥ 16.1.0 · ≤ 16.1.6
- ≥ 16.1.0 · ≤ 16.1.6
- ≥ 16.1.0 · ≤ 16.1.6
- ≥ 16.1.0 · ≤ 16.1.6
- ≥ 16.1.0 · ≤ 16.1.6
- ≥ 16.1.0 · ≤ 16.1.6
- ≥ 16.1.0 · ≤ 16.1.6
- ≥ 16.1.0 · ≤ 16.1.6
- ≥ 16.1.0 · ≤ 16.1.6
- ≥ 16.1.0 · ≤ 16.1.6
- ≥ 16.1.0 · ≤ 16.1.6
Configuration 5
OR
- ≥ 17.1.0 · ≤ 17.1.3
- ≥ 17.5.0 · ≤ 17.5.1
- ≥ 17.1.0 · ≤ 17.1.3
- ≥ 17.5.0 · ≤ 17.5.1
- ≥ 17.1.0 · ≤ 17.1.3
- ≥ 17.5.0 · ≤ 17.5.1
- ≥ 17.1.0 · ≤ 17.1.3
- ≥ 17.5.0 · ≤ 17.5.1
- ≥ 17.1.0 · ≤ 17.1.3
- ≥ 17.5.0 · ≤ 17.5.1
- ≥ 17.1.0 · ≤ 17.1.3
- ≥ 17.5.0 · ≤ 17.5.1
- ≥ 17.1.0 · ≤ 17.1.3
- ≥ 17.5.0 · ≤ 17.5.1
- ≥ 17.1.0 · ≤ 17.1.3
- ≥ 17.5.0 · ≤ 17.5.1
- ≥ 17.1.0 · ≤ 17.1.3
- ≥ 17.5.0 · ≤ 17.5.1
- ≥ 17.1.0 · ≤ 17.1.3
- ≥ 17.5.0 · ≤ 17.5.1
- ≥ 17.1.0 · ≤ 17.1.3
- ≥ 17.5.0 · ≤ 17.5.1
- ≥ 17.1.0 · ≤ 17.1.3
- ≥ 17.5.0 · ≤ 17.5.1
- ≥ 17.1.0 · ≤ 17.1.3
- ≥ 17.5.0 · ≤ 17.5.1
- ≥ 17.1.0 · ≤ 17.1.3
- ≥ 17.5.0 · ≤ 17.5.1
- ≥ 17.1.0 · ≤ 17.1.3
- ≥ 17.5.0 · ≤ 17.5.1
- ≥ 17.1.0 · ≤ 17.1.3
- ≥ 17.5.0 · ≤ 17.5.1
- ≥ 17.1.0 · ≤ 17.1.3
- ≥ 17.5.0 · ≤ 17.5.1
- ≥ 17.1.0 · ≤ 17.1.3
- ≥ 17.5.0 · ≤ 17.5.1
- ≥ 17.1.0 · ≤ 17.1.3
- ≥ 17.5.0 · ≤ 17.5.1
- ≥ 17.1.0 · ≤ 17.1.3
- ≥ 17.5.0 · ≤ 17.5.1
- ≥ 17.1.0 · ≤ 17.1.3
- ≥ 17.5.0 · ≤ 17.5.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-29999 Advisory
- https://my.f5.com/manage/s/article/K000159034 vendor-advisorypatchMitigationVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-29999 | Advisory | |
| https://my.f5.com/manage/s/article/K000159034 | vendor-advisorypatchMitigationVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner f5
Published May 13, 2026
Updated May 13, 2026
Reserved Apr 30, 2026
Link CVE-2026-42409
CISA Vulnrichment
Updated May 13, 2026
ENISA EUVD
EUVD-2026-29999 Assigner f5
Published May 13, 2026
Updated May 13, 2026
Exploited since n/a
Link EUVD-2026-29999