PT-2026-36290 · Open5Gs · Open5Gs

Ziyulin

·

Published

2026-05-01

·

Updated

2026-05-01

·

CVE-2026-7536

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Open5GS versions prior to 2.7.8
Description A remote denial of service can be triggered in the BSF component through the manipulation of the ipv4Addr argument. This issue occurs within the bsf sess add by ip address() function located in the '/nbsf-management/v1/pcfBindings' endpoint.
Recommendations Update to a version newer than 2.7.7. As a temporary workaround, restrict access to the '/nbsf-management/v1/pcfBindings' endpoint or limit the use of the ipv4Addr parameter.

Exploit

Fix

DoS

Improper Resource Release

Weakness Enumeration

Related Identifiers

CVE-2026-7536

Affected Products

Open5Gs