A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-41227

CVE-2026-41227: HTTP/2 Virtual Server DoS Vulnerability

CVE-2026-41227 is a denial of service flaw in HTTP/2 virtual servers with Layer 7 DoS Protection that causes memory consumption leading to TMM process termination. This article covers technical details, impact, and mitigation.

Published: May 17, 2026

CVE-2026-41227 Overview

CVE-2026-41227 is a denial-of-service vulnerability affecting F5 BIG-IP HTTP/2 virtual servers configured with Layer 7 DoS Protection. Undisclosed traffic patterns trigger uncontrolled memory growth in the Traffic Management Microkernel (TMM) process. The memory exhaustion forces TMM to terminate, disrupting traffic processing on the affected virtual server. The flaw maps to [CWE-770: Allocation of Resources Without Limits or Throttling]. F5 notes that software versions which have reached End of Technical Support (EoTS) are not evaluated. Refer to F5 Technical Article K000158979 for vendor guidance.

Critical Impact

A remote, unauthenticated attacker can terminate the TMM process on an HTTP/2 virtual server with Layer 7 DoS Protection enabled, disrupting application delivery and load balancing services.

Affected Products

  • F5 BIG-IP deployments running an HTTP/2 virtual server
  • BIG-IP configurations with Layer 7 DoS Protection enabled on the affected virtual server
  • Software versions still under F5 Technical Support (EoTS versions are not evaluated)

Discovery Timeline

  • 2026-05-13 - CVE-2026-41227 published to NVD
  • 2026-05-13 - Last updated in NVD database

Technical Details for CVE-2026-41227

Vulnerability Analysis

The vulnerability resides in the Traffic Management Microkernel (TMM), the core data-plane process of F5 BIG-IP. TMM handles connection state, protocol parsing, and policy enforcement, including Layer 7 DoS Protection. When an HTTP/2 virtual server processes specific undisclosed traffic, memory allocations associated with Layer 7 DoS Protection grow without an enforced ceiling. The runaway allocation pattern eventually exceeds available memory, prompting the operating system or watchdog to terminate TMM.

Termination of TMM interrupts all traffic flowing through the BIG-IP data plane on the affected instance. Customers relying on the device for ingress, load balancing, or WAF enforcement experience service disruption until TMM restarts and rebuilds state.

Root Cause

The root cause is missing resource throttling [CWE-770] in the code path that handles HTTP/2 traffic under Layer 7 DoS Protection. Memory allocated to track or mitigate suspect requests is not bounded against attacker-controlled inputs. Without enforced quotas or eviction logic, attacker traffic drives allocations until the process is killed.

Attack Vector

The attack vector is network-based and requires no authentication or user interaction. An attacker sends crafted HTTP/2 traffic toward a virtual server that has Layer 7 DoS Protection configured. The specific traffic pattern is not disclosed by F5. The result is a reliable denial-of-service condition against the data plane, impacting availability but not confidentiality or integrity. F5 has not published proof-of-concept code, and no public exploit is currently available.

No verified code examples are available for this vulnerability. Consult the F5 Technical Article K000158979 for vendor-supplied technical context.

Detection Methods for CVE-2026-41227

Indicators of Compromise

  • Unexpected TMM process restarts logged in /var/log/ltm or shown by tmsh show sys proc-info tmm
  • Sudden spikes in TMM resident memory followed by core dumps under /var/savecore/ or /shared/core/
  • Connection resets and traffic interruptions on HTTP/2 virtual servers coinciding with elevated request volume
  • High-rate or anomalous HTTP/2 stream patterns targeting virtual servers with Layer 7 DoS Protection profiles attached

Detection Strategies

  • Monitor BIG-IP system logs for TMM panic, segfault, or restart events and correlate with inbound HTTP/2 traffic volume
  • Baseline normal HTTP/2 request rates per virtual server and alert on deviations against virtual servers with DoS Protection profiles
  • Ingest BIG-IP syslog and SNMP telemetry into a centralized SIEM or data lake to identify repeated TMM termination patterns across the fleet

Monitoring Recommendations

  • Enable and forward tmm core file alerts and mcpd health notifications to your SOC
  • Track memory utilization of the TMM process with sub-minute granularity to surface rapid growth
  • Capture HTTP/2 frame-level telemetry on affected virtual servers to support post-incident traffic analysis

How to Mitigate CVE-2026-41227

Immediate Actions Required

  • Inventory all BIG-IP virtual servers that use HTTP/2 profiles combined with Layer 7 DoS Protection
  • Review F5 Technical Article K000158979 and apply the fixed version identified for your branch
  • Confirm that BIG-IP instances are not running End of Technical Support (EoTS) versions, which are not evaluated by F5
  • Restrict exposure of affected virtual servers behind upstream rate limiting or scrubbing where feasible

Patch Information

F5 publishes fixed software versions and mitigations in F5 Technical Article K000158979. Administrators should consult the advisory to identify the fixed release for their specific BIG-IP branch and schedule an upgrade through standard change management.

Workarounds

  • Disable Layer 7 DoS Protection on HTTP/2 virtual servers if it is not strictly required, accepting the loss of that mitigation
  • Disable HTTP/2 on affected virtual servers and fall back to HTTP/1.1 where application requirements permit
  • Place an upstream rate limiter or WAF in front of the BIG-IP to constrain HTTP/2 request volume per source
  • Apply source-IP allowlisting on management and high-value virtual servers to reduce attack surface
bash
# Identify virtual servers with HTTP/2 and DoS Protection profiles attached
tmsh list ltm virtual one-line | grep -E 'http2|dos'

# Temporarily detach the DoS profile from an affected virtual server
tmsh modify ltm virtual <vs_name> profiles delete { <dos_profile_name> }

# Or disable HTTP/2 by removing the HTTP/2 profile
tmsh modify ltm virtual <vs_name> profiles delete { http2 }
tmsh save sys config

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeDOS

  • Vendor/TechN/A

  • SeverityHIGH

  • CVSS Score8.7

  • EPSS Probability0.07%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-770
  • Technical References
  • F5 Technical Article K000158979
  • Latest CVEs
  • CVE-2026-9813: FlowIntel SSRF Vulnerability

  • CVE-2026-4377: D-Link DWR-X1820 Auth Bypass Vulnerability

  • CVE-2026-47074: ex_aws_sns Auth Bypass Vulnerability

  • CVE-2026-46241: Linux Kernel Use-After-Free Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English