CVE-2025-47148 MEDIUM

CVE-2025-47148: BIG-IP APM and SSL Orchestrator vulnerability

Vendor F5
Product BIG-IP
Weakness CWE-404
Published October 15, 2025
Last update February 26, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with single logout (SLO) enabled on an access policy, undisclosed requests can cause an increase in memory resource utilization.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Key dates

02Disclosure timeline

October 15, 2025 CVE published
February 26, 2026 Record updated