Last Modified: Sep 16, 2026
Affected Product(s):
BIG-IP APM
Known Affected Versions:
17.5.0, 17.5.1, 17.5.1.2, 17.5.1.3, 17.5.1.4, 17.5.1.5, 17.5.1.6, 17.5.1.8, 17.5.1.9
Opened: Jun 10, 2026 Severity: 2-Critical
On BIG-IP APM version 17.5.1, the OAuth/OIDC Provider Discovery task may intermittently fail. This occurs when McpRequestMultiCompletion receives more callbacks than expected from the doChainQuery() function. This results in an IllegalStateException, which can lead to an incomplete access-policy apply list. Consequently, one or more policies associated with the OAuth provider may be omitted from the apply operation
The issue requires: - BIG-IP APM with OAuth/OIDC Provider Discovery configured. - Multiple access policies associated with the same OAuth provider - An OIDC Discovery task execution - Extra MCP callbacks from the APM discovery worker - The issue is intermittent and timing-dependent
Affected access policies remain in the “Apply Access Policy: Required” state. Because newly discovered JWK keys may not be applied to those policies, JWT signature validation can fail, and users may be locked out of VPN or OAuth-protected applications
None
None