Use After Free Vulnerability in Open5GS by Open5GS
CVE-2026-90707

6.9MEDIUM

Key Information:

Vendor

Open5GS

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-90707?

A security flaw has been identified in Open5GS, affecting versions up to 2.7.x. The vulnerability resides in the function amf_nnrf_try_old_amf_discovery_fallback located in src/amf/nnrf-handler.c. An improper handling of the discovery_option argument may lead to a use after free condition, which can be exploited remotely. Users are advised to apply the patch identified by commit ddd683a35f8aaac2b7b9884a24cd53bddfc65238 to mitigate this issue.

Affected Version(s)

Open5GS 2.0

Open5GS 2.1

Open5GS 2.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

centauruszzz (VulDB User)
.