Denial of Service Vulnerability in Open5GS 2.7.0 by Open5GS
CVE-2026-71675

7.5HIGH

Key Information:

Vendor

Open5GS

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-71675?

A vulnerability has been identified in Open5GS v2.7.0 that allows a remote attacker to exploit the ngap_send_to_nas() function located in src/amf/ngap-path.c. This flaw can lead to a denial of service condition, potentially disrupting the availability of the service for legitimate users. It is essential for administrators using this version to assess their security posture and apply necessary mitigations.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.