PT-2026-38606 · Open5Gs · Open5Gs

Linziyu

·

Published

2026-05-08

·

Updated

2026-05-11

·

CVE-2026-8122

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Open5GS versions prior to 2.7.8
Description A remote denial of service issue exists in the NSSF component. The flaw is located in the ogs sbi discovery option add service names() function within the /lib/sbi/message.c library, where specific manipulation can cause the system to crash or become unavailable.
Recommendations As a temporary workaround, restrict access to the NSSF component or the ogs sbi discovery option add service names() function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8122

Affected Products

Open5Gs