Bug ID 2331657: APM OAuth OIDC Discovery extra callbacks cause access policies to be dropped

Last Modified: Sep 16, 2026

Affected Product(s):
BIG-IP APM(all modules)

Known Affected Versions:
17.5.0, 17.5.1, 17.5.1.2, 17.5.1.3, 17.5.1.4, 17.5.1.5, 17.5.1.6, 17.5.1.8, 17.5.1.9

Opened: Jun 10, 2026

Severity: 2-Critical

Symptoms

On BIG-IP APM version 17.5.1, the OAuth/OIDC Provider Discovery task may intermittently fail. This occurs when McpRequestMultiCompletion receives more callbacks than expected from the doChainQuery() function. This results in an IllegalStateException, which can lead to an incomplete access-policy apply list. Consequently, one or more policies associated with the OAuth provider may be omitted from the apply operation

Impact

The issue requires: - BIG-IP APM with OAuth/OIDC Provider Discovery configured. - Multiple access policies associated with the same OAuth provider - An OIDC Discovery task execution - Extra MCP callbacks from the APM discovery worker - The issue is intermittent and timing-dependent

Conditions

Affected access policies remain in the “Apply Access Policy: Required” state. Because newly discovered JWK keys may not be applied to those policies, JWT signature validation can fail, and users may be locked out of VPN or OAuth-protected applications

Workaround

None

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips