CVE-2025-46706

7.5

F5 · BIG-IP

An improper resource allocation vulnerability in F5 BIG-IP allows unauthenticated attackers to cause excessive memory consumption via crafted HTTP requests.

Executive summary

A vulnerability in F5 BIG-IP products allows unauthenticated remote attackers to trigger a denial of service by exhausting system memory resources.

Vulnerability

This is a resource exhaustion flaw (CWE-770) occurring when an iRule utilizes the HTTP::respond command, which fails to properly throttle memory allocation during request processing. An unauthenticated attacker can trigger this condition by sending undisclosed request patterns to a configured virtual server.

Business impact

Successful exploitation of this vulnerability leads to a denial of service condition by consuming critical memory resources. Given the CVSS score of 7.5, this high-severity flaw poses a significant risk to availability, potentially causing service outages for business-critical applications hosted behind the affected BIG-IP infrastructure.

Remediation

Immediate Action: Administrators should upgrade to the fixed software versions as specified in the F5 security advisory K000151611, specifically versions 17.5.0 or 15.1.0 for BIG-IP, and 2.0.0 for BIG-IP Next SPK and CNF.

Proactive Monitoring: Security teams should monitor system memory utilization metrics and review access logs for high volumes of unusual request patterns targeting virtual servers configured with iRules.

Compensating Controls: Deploy or tune existing Web Application Firewalls to inspect incoming traffic for malformed or suspicious HTTP requests that may trigger the vulnerable iRule command.

Exploitation status

Public Exploit Available: No — exploit_available (false).

Analyst recommendation

This vulnerability represents a high risk to infrastructure availability due to the ease of exploitation. IT administrators must prioritize patching the affected F5 BIG-IP instances to the recommended versions immediately to prevent potential service degradation or complete system failure.

More F5 CVEs

Sources

Originally found and disclosed by F5, per the CVE Program record.