Denial of Service Vulnerability in Open5GS by Open5GS
CVE-2026-2523
Key Information:
Badges
What is CVE-2026-2523?
A vulnerability affecting Open5GS versions up to 2.7.6 has been identified, specifically within the smf_gn_handle_create_pdp_context_request function located in src/smf/gn-handler.c. This vulnerability may allow an attacker to exploit reachable assertions, potentially leading to a Denial of Service situation. The attack can be initiated remotely, and the exploit has been publicly disclosed. Despite prior notification to the project regarding this issue, there has yet to be any official response from the developers.
Affected Version(s)
Open5GS 2.7.0
Open5GS 2.7.1
Open5GS 2.7.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
