CYBERSECURITYTRACKER
TRACKING7,931 stories in this site build1,728 vulnerability news stories in this site build
Permanent story citation

Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8369

As cited

Copy frozen at (site build).

vulnerabilities

Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)

F5 BIG-IP contains a heap buffer overflow in the Authorization header processing of its OAuth flow that allows unauthenticated remote code execution. The vulnerability (CVE-2026-94127, CVSS 9.3) results from missing bounds checking on the Authorization header size before copying it to a 0x4100-byte heap buffer; exploitation causes a crash that can be leveraged to overwrite heap metadata and hijack function pointers. The flaw affects BIG-IP APM versions 21.1.0, 17.5.0-17.5.1, and 17.1.0-17.1.3, with patches available as of September 22.

Why it matters: Organizations deploying F5 BIG-IP as an edge application delivery controller or remote access gateway face immediate risk of unauthenticated RCE from attackers sending oversized Authorization headers to the OAuth userinfo endpoint; this vulnerability is actively exploited in the wild and rated critical by CVSS and included in the known exploited vulnerabilities (KEV) catalog.

VendorsCitrixF5
Actorsplay
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary