Open5GS NRF context.c ogs_sbi_nf_service_add denial of service
Published May 17, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.81%
Description
A vulnerability was determined in Open5GS up to 2.7.7. Affected is the function ogs_sbi_subscription_data_add/ogs_sbi_nf_service_add in the library /lib/sbi/context.c of the component NRF. Executing a manipulation can lead to denial of service. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. This patch is called 819db11a08b9736a3576c4f99ceb28f7eb99523a. A patch should be applied to remediate this issue.
Affected products
-
- Version 2.7.0StatusaffectedConstraints-
- Version 2.7.1StatusaffectedConstraints-
- Version 2.7.2StatusaffectedConstraints-
- Version 2.7.3StatusaffectedConstraints-
- Version 2.7.4StatusaffectedConstraints-
- Version 2.7.5StatusaffectedConstraints-
- Version 2.7.6StatusaffectedConstraints-
- Version 2.7.7StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30690 Advisory
- https://github.com/open5gs/open5gs/ product
- https://github.com/open5gs/open5gs/commit/819db11a08b9736a3576c4f99ceb28f7eb99523a patch
- https://github.com/open5gs/open5gs/issues/4465 issue-trackingExploitIssue Tracking
- https://github.com/open5gs/open5gs/issues/4466 exploitissue-trackingIssue Tracking
- https://github.com/open5gs/open5gs/pull/4534 issue-trackingpatchIssue Tracking
- https://vuldb.com/submit/817029 third-party-advisoryThird Party AdvisoryVDB Entry
- https://vuldb.com/submit/817030 third-party-advisoryThird Party AdvisoryVDB Entry
- https://vuldb.com/vuln/364331 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/vuln/364331/cti signaturepermissions-requiredPermissions RequiredVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30690 | Advisory | |
| https://github.com/open5gs/open5gs/ | product | |
| https://github.com/open5gs/open5gs/commit/819db11a08b9736a3576c4f99ceb28f7eb99523a | patch | |
| https://github.com/open5gs/open5gs/issues/4465 | issue-trackingExploitIssue Tracking | |
| https://github.com/open5gs/open5gs/issues/4466 | exploitissue-trackingIssue Tracking | |
| https://github.com/open5gs/open5gs/pull/4534 | issue-trackingpatchIssue Tracking | |
| https://vuldb.com/submit/817029 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://vuldb.com/submit/817030 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://vuldb.com/vuln/364331 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/vuln/364331/cti | signaturepermissions-requiredPermissions RequiredVDB Entry |
Change history (0)
No recorded changes yet.