PT-2026-41538 · Open5Gs · Open5Gs

·

CVE-2026-8746

·

Published

2026-05-17

·

Updated

2026-05-18

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Open5GS versions prior to 2.7.8
Description A use after free flaw exists in the NRF component within the discover handler() function located in the /lib/sbi/nghttp2-server.c library. This issue allows a remote attacker to manipulate the system, potentially leading to a crash or unauthorized code execution. Use after free occurs when an application continues to use a pointer after it has been freed, which can corrupt memory.
Recommendations Update to a version newer than 2.7.7. As a temporary workaround, restrict access to the NRF component to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8746

Affected Products

Open5Gs