MEDIUM
Open5GS AUSF nausf-handler.c ogs_timer_add denial of service
Published May 17, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.68%
Description
A vulnerability was identified in Open5GS up to 2.7.7. Affected by this vulnerability is the function ogs_timer_add in the library /src/ausf/nausf-handler.c of the component AUSF. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected products
-
- Version 2.7.0StatusaffectedConstraints-
- Version 2.7.1StatusaffectedConstraints-
- Version 2.7.2StatusaffectedConstraints-
- Version 2.7.3StatusaffectedConstraints-
- Version 2.7.4StatusaffectedConstraints-
- Version 2.7.5StatusaffectedConstraints-
- Version 2.7.6StatusaffectedConstraints-
- Version 2.7.7StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://github.com/open5gs/open5gs/ product
- https://github.com/open5gs/open5gs/issues/4472 exploitissue-trackingIssue Tracking
- https://vuldb.com/submit/817031 third-party-advisoryThird Party AdvisoryVDB Entry
- https://vuldb.com/vuln/364332 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/vuln/364332/cti signaturepermissions-requiredPermissions RequiredVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://github.com/open5gs/open5gs/ | product | |
| https://github.com/open5gs/open5gs/issues/4472 | exploitissue-trackingIssue Tracking | |
| https://vuldb.com/submit/817031 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://vuldb.com/vuln/364332 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/vuln/364332/cti | signaturepermissions-requiredPermissions RequiredVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published May 17, 2026
Updated May 18, 2026
Reserved May 16, 2026
Link CVE-2026-8745
CISA Vulnrichment
Updated May 18, 2026