CVE-2026-8248
Denial of Service in Open5GS SMF Component
Publication date: 2026-05-10
Last updated on: 2026-05-10
Assigner: VulDB
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| open5gs | open5gs | to 2.7.7 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-404 | The product does not release or incorrectly releases a resource before it is made available for re-use. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in Open5GS versions up to 2.7.7, specifically in the function update_authorized_pcc_rule_and_qos within the file /src/smf/npcf-handler.c of the SMF component.
The issue allows an attacker to manipulate this function, resulting in a denial of service condition.
The attack can be launched remotely, and the exploit is publicly available.
How can this vulnerability impact me? :
The vulnerability can cause a denial of service (DoS) in the affected Open5GS system.
This means that the system or service relying on Open5GS may become unavailable or unresponsive, potentially disrupting network functions.