PT-2026-40651 · F5 · Big-Ip Next For Kubernetes+3

Published

2026-05-13

·

Updated

2026-05-22

·

CVE-2026-40629

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions F5 BIG-IP versions prior to 17.1.3.1 F5 BIG-IP versions prior to 17.5.1.4 BIG-IP Next SPK (affected versions not specified) BIG-IP Next CNF (affected versions not specified) BIG-IP Next for Kubernetes (affected versions not specified)
Description When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections due to an issue with the allocation of resources.
Recommendations Update F5 BIG-IP to version 17.1.3.1 or later. Update F5 BIG-IP to version 17.5.1.4 or later. At the moment, there is no information about a newer version that contains a fix for this vulnerability for BIG-IP Next SPK, BIG-IP Next CNF, and BIG-IP Next for Kubernetes.

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40629

Affected Products

Big-Ip
Big-Ip Next Cnf
Big-Ip Next Spk
Big-Ip Next For Kubernetes