CVE-2025-46706
7.5F5 · BIG-IP
An improper resource allocation vulnerability in F5 BIG-IP allows unauthenticated attackers to cause excessive memory consumption via crafted HTTP requests.
Executive summary
A vulnerability in F5 BIG-IP products allows unauthenticated remote attackers to trigger a denial of service by exhausting system memory resources.
Vulnerability
This is a resource exhaustion flaw (CWE-770) occurring when an iRule utilizes the HTTP::respond command, which fails to properly throttle memory allocation during request processing. An unauthenticated attacker can trigger this condition by sending undisclosed request patterns to a configured virtual server.
Business impact
Successful exploitation of this vulnerability leads to a denial of service condition by consuming critical memory resources. Given the CVSS score of 7.5, this high-severity flaw poses a significant risk to availability, potentially causing service outages for business-critical applications hosted behind the affected BIG-IP infrastructure.
Remediation
Immediate Action: Administrators should upgrade to the fixed software versions as specified in the F5 security advisory K000151611, specifically versions 17.5.0 or 15.1.0 for BIG-IP, and 2.0.0 for BIG-IP Next SPK and CNF.
Proactive Monitoring: Security teams should monitor system memory utilization metrics and review access logs for high volumes of unusual request patterns targeting virtual servers configured with iRules.
Compensating Controls: Deploy or tune existing Web Application Firewalls to inspect incoming traffic for malformed or suspicious HTTP requests that may trigger the vulnerable iRule command.
Exploitation status
Public Exploit Available: No — exploit_available (false).
Analyst recommendation
This vulnerability represents a high risk to infrastructure availability due to the ease of exploitation. IT administrators must prioritize patching the affected F5 BIG-IP instances to the recommended versions immediately to prevent potential service degradation or complete system failure.
More F5 CVEs
Sources
Originally found and disclosed by F5, per the CVE Program record.