Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3145 articles · 183352 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-59762EXPLOITEDPATCHED
f5 · big-ip

BIG-IP HTTP/2 vulnerability

Description

When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization under stalled flow-control conditions. Specifically, a remote, unauthenticated attacker can trigger memory exhaustion by using standard flow-control parameters such as SETTINGS_INITIAL_WINDOW_SIZE = 0 to stall outbound data for multiple simultaneous request streams. The server continues processing requests and generating complete response bodies even though it is unable to transmit them, causing response data to remain buffered in memory. Each stalled stream retains its allocated buffer until the connection closes or a timeout occurs. An attacker can exploit this by opening many simultaneous streams and requesting large resources, causing accumulation of large amounts of buffered response data. Impact: System performance can degrade until the TMM process is either forced to restart or is manually restarted. In environments with permissive resource limits, this can lead to excessive memory consumption, swap exhaustion, service instability, and system crashes. Under default or lower limits, the attack can exhaust available connections or worker resources, temporarily preventing new clients from establishing sessions. This vulnerability allows a remote, unauthenticated attacker to cause a degradation of service that can lead to a denial-of-service (DoS) on the BIG-IP system. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected Products

VendorProductVersions
f5big-ip21.1.0, 21.0.0, 17.5.0, 17.1.0, 2.3.0, 2.0.0, 1.9.0, 1.7.0, 2.3.0, 2.0.0, 1.1.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
f5big-ipcert_advisory90%

References

  • https://my.f5.com/manage/s/article/K000162231(vendor-advisory, patch)

Related News (3 articles)

Tier B
CERT/CC Vuln Notes17d ago
VU#885548: Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions
→ No new info (linked only)
Tier B
BSI Advisories18d ago
[NEU] [mittel] F5 BIG-IP und BIG-IP Next: Schwachstelle ermöglicht Denial of Service
→ No new info (linked only)
Tier C
VulDB19d ago
CVE-2026-59762 | F5 BIG-IP HTTP 2 denial of service
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
21.1.0.121.0.0.317.5.1.817.1.3.42.3.22.2.3*1.7.181.4.3
CWECWE-770
PublishedJul 15, 2026
Last enriched17d agov3
Tags
CVE-2026-59762
Trending Score5
Source articles3
Independent3
Info Completeness10/14
Missing: epss, kev, exploit, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-42945EXPKEV
NGINX ngx_http_rewrite_module vulnerability
Trending: 141
HIGHCVE-2026-9256EXP
NGINX ngx_http_rewrite_module vulnerability
Trending: 15
LOWCVE-2026-60065EXP
NGINX Plus ngx_stream_mqtt_filter_module vulnerability
Trending: 4
MEDIUMCVE-2026-60062EXP
NGINX Agent Vulnerability
Trending: 3
HIGHCVE-2026-55723EXP
NGINX Ingress Controller vulnerability
Trending: 3

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 15, 2026
Discovered by ZDM
Jul 15, 2026
Updated: severity, activelyExploited, tags
Jul 15, 2026
Actively Exploited
Jul 15, 2026
Patch Available
Jul 15, 2026
Updated: description, mitreAttack
Jul 16, 2026

Version History

v3
Last enriched 17d ago
v3Tier B17d ago

Added technical details on stalled flow-control attack mechanism (SETTINGS_INITIAL_WINDOW_SIZE = 0) and added MITRE ATT&CK technique T1499.004 (Application Exhaustion)

descriptionmitreAttack
via CERT/CC Vuln Notes
v2Tier C19d ago

Updated severity to CRITICAL, marked as actively exploited, and added new products and CVE ID.

severityactivelyExploitedtags
via VulDB
v119d ago

Initial creation