Bug ID 1989133: Unexpected blocking of valid login attempts after upgrade to version 17.5.0

Last Modified: Oct 15, 2025

Affected Product(s):
BIG-IP ASM(all modules)

Known Affected Versions:
17.5.0, 17.5.1, 17.5.1.2, 17.5.1.3

Opened: Jul 18, 2025

Severity: 3-Major

Symptoms

Users may experience blocking of legitimate login attempts due to incorrect classification of failed logins.

Impact

Valid login attempts may be falsely flagged as brute force attacks, triggering enforcement actions such as CAPTCHA or blocking pages, potentially disrupting user access.

Conditions

Occurs when brute force protection is enabled and login attempts are made to a configured login URL without authentication headers.

Workaround

None

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips