security1 publisher
F5 fixes CVE-2026-94127 by capping the Authorization header at 16,640 bytes
watchTowr diffed two builds of BIG-IP's tmm64 and found that F5's fix for CVE-2026-94127 is a single length test on the Authorization header, a field parsed at the edge. watchTowr says attackers were already exploiting it.
Publishers:labs.watchtowr.com
Reality
- Evidence62
- Adoption20
- Hype gap+18
- Incentives55
- Confidence55