As cited
Copy frozen at (site build).
vulnerabilities
Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)
F5 BIG-IP contains a heap buffer overflow in the Authorization header processing of its OAuth flow that allows unauthenticated remote code execution. The vulnerability (CVE-2026-94127, CVSS 9.3) results from missing bounds checking on the Authorization header size before copying it to a 0x4100-byte heap buffer; exploitation causes a crash that can be leveraged to overwrite heap metadata and hijack function pointers. The flaw affects BIG-IP APM versions 21.1.0, 17.5.0-17.5.1, and 17.1.0-17.1.3, with patches available as of September 22.
Why it matters: Organizations deploying F5 BIG-IP as an edge application delivery controller or remote access gateway face immediate risk of unauthenticated RCE from attackers sending oversized Authorization headers to the OAuth userinfo endpoint; this vulnerability is actively exploited in the wild and rated critical by CVSS and included in the known exploited vulnerabilities (KEV) catalog.
- Source published
- First seen by Cybersecurity Tracker