VYPR
Unrated severityNVD Advisory· Published Oct 15, 2025· Updated Feb 26, 2026

BIG-IP Advanced WAF and ASM bd process vulnerability

CVE-2025-61938

Description

When a BIG-IP Advanced WAF or ASM security policy is configured with a URL greater than 1024 characters in length for the Data Guard Protection Enforcement setting, either manually or through the automatic Policy Builder, the bd process can terminate repeatedly.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected products

1
  • F5/BIG-IPv5
    Range: 17.5.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.