HTTP and TCP Router Vulnerability in Fabio by F5 Networks
CVE-2026-62987

5.8MEDIUM

Key Information:

Vendor

Fabiolb

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-62987?

Fabio, an HTTP(S) and TCP router by F5 Networks, has a vulnerability that allows unauthenticated clients to manipulate crucial headers such as ClientIPHeader, TLSHeader, and RequestID. This can lead to a loss of important signals used for authorization and auditing in backend systems, undermining the integrity of the application. The vulnerability affects versions 1.6.6 through 1.7.2, excluding the hardcoded protected headers. It is essential for users to update their installations to version 1.7.2 to mitigate potential security risks.

Affected Version(s)

fabio >= 1.6.6, < 1.7.2

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.