Description
A vulnerability was detected in Open5GS up to 2.7.7. Impacted is the function ogs_sbi_stream_find_by_id in the library /lib/sbi/nghttp2-server.c of the component NSSF. Performing a manipulation results in denial of service. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-05-08
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Open5GS NSSF component function ogs_sbi_stream_find_by_id within nghttp2-server.c causes the system to crash or hang when presented with a crafted input. The weakness, classified as CWE-404 (Missing Reference), creates a denial of service that stops the NSSF service from responding to normal traffic. The impact is a loss of availability for all users that depend on the NSSF function. The exploit requires locally‑executed manipulation, so an attacker must already have administrative or root access to the host to trigger the failure.

Affected Systems

Open5GS installations using version 2.7.7 or earlier are affected, as the vulnerability exists in the NSSF component of the platform. No additional sub‑product details are provided beyond the Open5GS project; all these versions across supported operating systems are potentially impacted when running the NSSF service.

Risk and Exploitability

The CVSS v3.1 score of 4.8 indicates a moderate severity. No EPSS score is published, so the likelihood of exploitation remains uncertain. The flaw is not listed in the CISA KEV catalog and demands local access, which reduces the appeal for external attackers. However, because the exploit is public and anyone with local privilege can trigger it, the risk for systems with compromised accounts or insecure local access is significant.

Generated by OpenCVE AI on May 8, 2026 at 02:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Open5GS to a release newer than 2.7.7 that contains the fix for the ogs_sbi_stream_find_by_id vulnerability.
  • If an immediate upgrade is not possible, isolate the NSSF service in a dedicated host or container and restrict local access to only trusted administrative users.
  • Monitor NSSF logs for repeated denial‑of‑service attempts and apply temporary resource limits to the NSSF process until a permanent patch is applied.

Generated by OpenCVE AI on May 8, 2026 at 02:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 08 May 2026 01:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Open5GS up to 2.7.7. Impacted is the function ogs_sbi_stream_find_by_id in the library /lib/sbi/nghttp2-server.c of the component NSSF. Performing a manipulation results in denial of service. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title Open5GS NSSF nghttp2-server.c ogs_sbi_stream_find_by_id denial of service
First Time appeared Open5gs
Open5gs open5gs
Weaknesses CWE-404
CPEs cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*
Vendors & Products Open5gs
Open5gs open5gs
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-08T00:00:21.852Z

Reserved: 2026-05-07T16:56:41.625Z

Link: CVE-2026-8119

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-08T01:16:08.367

Modified: 2026-05-08T01:16:08.367

Link: CVE-2026-8119

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-08T03:00:08Z

Weaknesses