Skip to content
CodeAuditAgent

CVE-2026-40435

When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blocked addresses. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Weakness

When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blocked addresses. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected products

  • f5 big-ip_access_policy_manager
  • f5 big-ip_advanced_firewall_manager
  • f5 big-ip_advanced_web_application_firewall
  • f5 big-ip_analytics
  • f5 big-ip_application_acceleration_manager
  • f5 big-ip_application_security_manager
  • f5 big-ip_application_visibility_and_reporting
  • f5 big-ip_automation_toolchain

References

Find the bug before an attacker does.

Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.