MEDIUM
Open5GS BSF context.c bsf_sess_find_by_ipv6prefix denial of service
Published May 1, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.47%
Description
A flaw has been found in Open5GS up to 2.7.7. This issue affects the function bsf_sess_find_by_ipv6prefix of the file /src/bsf/context.c of the component BSF. This manipulation of the argument ipv6Prefix causes denial of service. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected products
-
Affected
- 2.7.0
- 2.7.1
- 2.7.2
- 2.7.3
- 2.7.4
- 2.7.5
- 2.7.6
- 2.7.7
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26661 Advisory
- https://github.com/open5gs/open5gs/ product
- https://github.com/open5gs/open5gs/issues/4401 exploitissue-tracking
- https://vuldb.com/submit/804322 third-party-advisory
- https://vuldb.com/vuln/360530 vdb-entrytechnical-description
- https://vuldb.com/vuln/360530/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26661 | Advisory | |
| https://github.com/open5gs/open5gs/ | product | |
| https://github.com/open5gs/open5gs/issues/4401 | exploitissue-tracking | |
| https://vuldb.com/submit/804322 | third-party-advisory | |
| https://vuldb.com/vuln/360530 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/360530/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published May 1, 2026
Updated May 1, 2026
Reserved May 1, 2026
Link CVE-2026-7583
CISA Vulnrichment
Updated May 1, 2026
Red Hat
No data
GitHub
No data