F5
F5 Big-ip Next Service Proxy FOR Kubernetes: vulnerabilities and CVEs
F5 Big-ip Next Service Proxy FOR Kubernetes has 24 published vulnerabilities, 11 of them in the last 12 months. 0 are rated critical and 1 are listed by CISA as actively exploited.
CVEs24
Last 12 months11
Critical0
Actively exploited1
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-44487 | High (7.5) | 100% | ⚠ Active exploitation | Oct 10, 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59762 | High (8.7) | 0.57% | — | Jul 15, 2026 | When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Impact: System performance can degrade until the TMM process is either forced to… |
| CVE-2026-40629 | High (8.7) | 0.46% | — | May 13, 2026 | When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections. Note: Software versions which have reached End of Technical Support… |
| CVE-2026-40618 | High (8.7) | 0.46% | — | May 13, 2026 | When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to… |
| CVE-2025-61990 | High (8.7) | 0.35% | — | Oct 15, 2025 | When using a multi-bladed platform with more than one blade, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support… |
| CVE-2025-61974 | High (8.7) | 0.46% | — | Oct 15, 2025 | When a client SSL profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not… |
| CVE-2025-60016 | High (8.7) | 0.44% | — | Oct 15, 2025 | When Diffie-Hellman (DH) group Elliptic Curve Cryptography (ECC) Brainpool curves are configured in an SSL profile's Cipher Rule or Cipher Group, and that profile is applied to a virtual server, undisclosed traffic can… |
| CVE-2025-58120 | High (8.7) | 0.35% | — | Oct 15, 2025 | When HTTP/2 Ingress is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
| CVE-2025-55670 | High (7.1) | 0.31% | — | Oct 15, 2025 | On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End… |
| CVE-2025-54805 | Medium (6) | 0.31% | — | Oct 15, 2025 | When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process can cause an increase in the Traffic Management Microkernel (TMM) memory resource utilization. Note:… |
| CVE-2025-48008 | High (8.7) | 0.44% | — | Oct 15, 2025 | When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to… |
| CVE-2025-46706 | High (8.7) | 0.43% | — | Oct 15, 2025 | When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of… |
| CVE-2025-54500 | Medium (6.9) | 0.50% | — | Aug 13, 2025 | An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack). Note: Software versions which… |
| CVE-2025-41414 | High (8.7) | 0.41% | — | May 7, 2025 | When HTTP/2 client and server profile is configured on a virtual server, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated |
| CVE-2025-41399 | High (8.7) | 0.41% | — | May 7, 2025 | When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of… |
| CVE-2025-36557 | High (8.7) | 0.41% | — | May 7, 2025 | When an HTTP profile with the Enforce RFC Compliance option is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have… |
| CVE-2025-36504 | High (8.7) | 0.42% | — | May 7, 2025 | When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support… |
| CVE-2025-22846 | High (8.7) | 0.41% | — | Feb 5, 2025 | When SIP Session and Router ALG profiles are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have… |
| CVE-2024-41164 | High (8.2) | 0.44% | — | Aug 14, 2024 | When TCP profile with Multipath TCP enabled (MPTCP) is configured on a Virtual Server, undisclosed traffic along with conditions beyond the attackers control can cause TMM to terminate. Note: Software versions which… |
| CVE-2024-23314 | High (7.5) | 0.52% | — | Feb 14, 2024 | When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support… |
| CVE-2023-45886 | High (7.5) | 1.4% | — | Nov 21, 2023 | The BGP daemon (bgpd) in IP Infusion ZebOS through 7.10.6 allow remote attackers to cause a denial of service by sending crafted BGP update messages containing a malformed attribute. |
| CVE-2023-44487 | High (7.5) | 100% | ⚠ Active exploitation | Oct 10, 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
| CVE-2023-45226 | High (7.4) | 0.38% | — | Oct 10, 2023 | The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacker with the ability to intercept traffic to impersonate the SPK Secure… |
| CVE-2023-40534 | High (7.5) | 0.54% | — | Oct 10, 2023 | When a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, and an iRule using the HTTP_REQUEST event or Local Traffic Policy are associated with the virtual server, undisclosed… |
| CVE-2023-24594 | Medium (5.3) | 0.56% | — | May 3, 2023 | When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization. Note: Software versions which have reached End of Technical Support (EoTS)… |
Other products by F5
Big-ip Access Policy Manager · 630Big-ip Application Security Manager · 581Big-ip Advanced Firewall Manager · 552Big-ip Local Traffic Manager · 541Big-ip Policy Enforcement Manager · 533Big-ip Link Controller · 525Big-ip Application Acceleration Manager · 524Big-ip Analytics · 511Big-ip Global Traffic Manager · 490Big-ip Domain Name System · 469Big-ip Fraud Protection Service · 405Big-ip Webaccelerator · 297