PT-2026-45142 · Open5Gs · Open5Gs

·

CVE-2026-10156

·

Published

2026-04-24

·

Updated

2026-05-31

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Open5GS versions prior to 2.7.8
Description A remote resource consumption issue exists in the nf-instances endpoint. The problem occurs within the handle amf info() function located in the /lib/sbi/nnrf-handler.c library. A remote attacker can trigger this by manipulating the nf info pool argument.
Recommendations Update to a version later than 2.7.7. As a temporary workaround, restrict access to the handle amf info() function to minimize the risk of exploitation.

Exploit

Fix

Improper Resource Release

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07824
CVE-2026-10156

Affected Products

Open5Gs