Description
In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wide denial of service.
Published: 2026-07-14
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Open5GS versions up to 2.7.7 contain a heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler that can lead to a subscriber-wide denial of service. The flaw occurs before authentication, allowing a crafted NAS message to read arbitrary memory locations and consequently crash the AMF, disrupting mobile network services for all subscribers served by that AMF instance.

Affected Systems

The vulnerability affects the Open5GS open5gs project, specifically releases 2.7.7 and earlier. No other vendors or product versions are listed as impacted.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity, while the EPSS score of less than 1 % suggests that exploitation is currently rare and likely requires a highly targeted attack. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves a remote adversary who can send crafted NAS messages to the AMF before authentication, triggering the out-of-bounds read that results in denial of service for all subscribers processed by that AMF instance.

Generated by OpenCVE AI on July 31, 2026 at 05:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Open5GS to a version newer than 2.7.7 to apply the vendor’s patch.
  • Disable the AMF NAS mobile‑identity handler if possible until a fixed release is available.
  • Implement network-level filtering or rate limiting of NAS traffic to mitigate potential denial of service until the patch is applied.

Generated by OpenCVE AI on July 31, 2026 at 05:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Open5gs
Open5gs open5gs
Vendors & Products Open5gs
Open5gs open5gs

Wed, 15 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Description In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wide denial of service.
Title Pre-auth heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat-cnalr

Published:

Updated: 2026-07-15T14:02:22.116Z

Reserved: 2026-07-14T12:29:33.633Z

Link: CVE-2026-15720

cve-icon Vulnrichment

Updated: 2026-07-15T14:02:18.910Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:00:16Z

Weaknesses