CVE-2026-34019 PUBLISHED

BIG-IP BFD vulnerability

Assigner: f5
Reserved: 30.04.2026 Published: 13.05.2026 Updated: 13.05.2026

When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to stop processing BFD packets and cause the configured routing protocol to fail over.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVSS Score: 6.3

Product Status

Vendor F5
Product BIG-IP
Versions Default: unknown
  • unaffected from 21.0.0 to * (excl.)
  • affected from 17.5.0 to 17.5.1 (excl.)
  • affected from 17.1.0 to 17.1.3 (excl.)
  • affected from 16.1.0 to * (excl.)

Credits

  • F5 finder

References

Problem Types

  • CWE-410: Insufficient Resource Pool CWE