Denial of Service Vulnerability in Open5GS by Open5GS
CVE-2026-8225
Key Information:
Badges
What is CVE-2026-8225?
A vulnerability exists in the Open5GS framework up to version 2.7.7, specifically within the function pcf_npcf_smpolicycontrol_handle_delete found in the file src/pcf/sm-sm.c. This security flaw allows malicious actors to initiate a denial of service attack remotely. The exploit method is available in public domains, increasing its potential risk for users. Despite having been reported early through an issue tracking system, the project maintainers have yet to provide a resolution.
Affected Version(s)
Open5GS 2.7.0
Open5GS 2.7.1
Open5GS 2.7.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
