A vulnerability was identified in F5 Products. A remote attacker could exploit this vulnerability to trigger denial of service condition on the targeted system. Note: No patch is currently available for CVE-2026-42534 of the affected products. Hence, ... Impact Denial of Service System / Technologies affected BIG-IP Next SPK 2.0.0 - 2.0.3 1.7.0 - 1.9.2 BIG-IP Next CNF 2.0.0 - 2.3.2 1.1.0 - 1.4.3 BIG-IP Next for Kubernetes 2.0.0 - 2.3.2 BIG-IP DNS 21.1.0 3 17.5.0 - 17.5.1 3 17.1.0 - 17.1.3 3 Solutions Notes: No patch is currently available. Workaround: Mitigate the vulnerability of attacks by following workaround: Restrict upstream DNS servers. Ensure that the DNS cache resolvers on your BIG-IP systems are configured to query only trusted, internal DNS servers. Use DNS over Transport Layer Security (TLS) . If supported, configure DNS resolution over TLS to prevent man-in-the-middle (MITM) attacks on the DNS path that could inject crafted Extension Mechanisms for DNS (EDNS) responses. Network segmentation: Isolate the DNS resolution path so that upstream DNS servers are on a trusted, protected network segment. Limit DNS features: If provisioning DNS or DNS cache resolution are not required, disable them to eliminate the attack surface entirely. Please visit the vendor web-site for more details. Apply workarounds issued by the vendor: https://my.f5.com/manage/s/article/K000162784
A remote attacker can exploit a denial-of-service vulnerability (CVE-2026-42534, CVSS 5.3 MEDIUM) in F5 products by triggering a condition through crafted DNS traffic. The vulnerability affects nlnetlabs unbound versions prior to 1.25.1. A fix is available by upgrading to unbound version 1.25.1; until that can be applied, mitigation includes restricting upstream DNS servers to trusted internal sources, implementing DNS over TLS, and employing network segmentation for the DNS resolution path.