Denial of Service Vulnerability in Open5GS Products by Open5GS
CVE-2026-7518

5.3MEDIUM

Key Information:

Vendor

Open5GS

Status
Vendor
CVE Published:
1 May 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-7518?

A vulnerability exists in Open5GS versions up to 2.7.7, where the function amf_namf_callback_handle_sdm_data_change_notify in the AMF SBI Endpoint allows an attacker to manipulate the argument changeItem.newValue, potentially leading to a denial of service. This vulnerability can be exploited remotely, allowing for significant disruption. The Open5GS team was notified of this issue; however, no resolution has been provided as of yet. The exploit details have been disclosed publicly, indicating the urgency for users to assess their risk and implement appropriate security measures.

Affected Version(s)

Open5GS 2.7.0

Open5GS 2.7.1

Open5GS 2.7.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

ZiyuLin (VulDB User)
VulDB CNA Team
.