Description
A flaw has been found in Open5GS up to 2.7.7. This vulnerability affects the function smf_nsmf_handle_created_data_in_vsmf of the component SMF. This manipulation causes denial of service. The attack may be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-05-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw exists in Open5GS versions up to 2.7.7 that corrupts the processing of data in the smf_nsmf_handle_created_data_in_vsmf function within the SMF component. The manipulation of this entry point can cause the service to crash, leading to a denial of service. The vulnerability is categorized as a CWE‑404 weakness, reflecting an error handling defect that allows an attacker to induce a failure state. Attackers can exploit the flaw remotely using a crafted payload published for public use.

Affected Systems

The affected vendor is Open5GS, with the product Open5GS. All releases from the initial release through 2.7.7 are vulnerable; later releases are presumed fixed but should be confirmed.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The attack can be executed over the network without local access, and an exploit has been released in the wild. Because the flaw leads to a service crash, the impact is immediate loss of service for the affected SMF component and potentially any dependent functions that rely on it.

Generated by OpenCVE AI on May 11, 2026 at 04:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest Open5GS release (2.8 or newer) that removes the vulnerable smf_nsmf_handle_created_data_in_vsmf logic.
  • If an immediate upgrade is not possible, temporarily disable the SMF component or block inbound traffic to its listening ports to reduce exposure.
  • Monitor your network for repeated connection attempts to the SMF endpoint and trigger alerts; apply the official vendor patch as soon as it is available.

Generated by OpenCVE AI on May 11, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 11 May 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 11 May 2026 03:30:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Open5GS up to 2.7.7. This vulnerability affects the function smf_nsmf_handle_created_data_in_vsmf of the component SMF. This manipulation causes denial of service. The attack may be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title Open5GS SMF smf_nsmf_handle_created_data_in_vsmf denial of service
First Time appeared Open5gs
Open5gs open5gs
Weaknesses CWE-404
CPEs cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*
Vendors & Products Open5gs
Open5gs open5gs
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-11T14:18:13.118Z

Reserved: 2026-05-10T15:44:26.657Z

Link: CVE-2026-8267

cve-icon Vulnrichment

Updated: 2026-05-11T14:17:04.070Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-05-11T04:16:20.233

Modified: 2026-05-11T15:10:16.663

Link: CVE-2026-8267

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-11T04:30:27Z

Weaknesses