PT-2026-39565 · Open5Gs · Open5Gs

Franklin

·

Published

2026-05-11

·

Updated

2026-05-11

·

CVE-2026-8266

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Open5GS versions prior to 2.7.8
Description A denial of service issue exists in the SMF component. A remote attacker can trigger this by manipulating the gsm build pdu session establishment accept() function within the /src/smf/gsm-build.c file during PDU Session Establishment.
Recommendations As a temporary workaround, restrict access to the SMF component or the gsm build pdu session establishment accept() function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Improper Resource Release

Weakness Enumeration

Related Identifiers

CVE-2026-8266

Affected Products

Open5Gs