Description
A security vulnerability has been detected in Open5GS up to 2.7.7. The impacted element is the function ogs_sbi_discovery_option_parse_plmn_list in the library /lib/sbi/conv.c of the component NRF. Such manipulation of the argument target-plmn-list leads to denial of service. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-05-17
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A denial‑of‑service vulnerability exists in Open5GS versions up to 2.7.7. The bug is in the function ogs_sbi_discovery_option_parse_plmn_list within the NRF component’s /lib/sbi/conv.c module. By manipulating the target‑plmn‑list argument, an attacker can cause the NRF service to crash or become unresponsive. The vendor has documented this issue in public issue trackers, and the vulnerability can be exploited remotely, as the affected function is reachable over the network.

Affected Systems

Open5GS (NRF component) with all releases up to and including 2.7.7 are impacted. No information about a fixed release is available, so any version up to and including 2.7.7 remains vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. EPSS data is unavailable, so the likelihood of exploitation is unknown, and the vulnerability is not listed in CISA’s KEV catalog. The vulnerability is exploitable remotely by submitting crafted target‑plmn‑list data, leading to service interruption. Because the attack is remote and the impact is denial of service, the risk to uptime and availability is significant for operators relying on continuous NRF operation.

Generated by OpenCVE AI on May 17, 2026 at 04:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or upgrade to a release that addresses the crash in ogs_sbi_discovery_option_parse_plmn_list.
  • Restrict external access to the NRF service by configuring firewall rules or network segmentation to limit exposure until the fix is applied.
  • Monitor system logs for repeated attempts to call NRF discovery with malformed PLMN lists and block or slow down suspicious traffic to mitigate potential denial‑of‑service attempts.

Generated by OpenCVE AI on May 17, 2026 at 04:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 17 May 2026 03:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Open5GS up to 2.7.7. The impacted element is the function ogs_sbi_discovery_option_parse_plmn_list in the library /lib/sbi/conv.c of the component NRF. Such manipulation of the argument target-plmn-list leads to denial of service. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title Open5GS NRF conv.c ogs_sbi_discovery_option_parse_plmn_list denial of service
First Time appeared Open5gs
Open5gs open5gs
Weaknesses CWE-404
CPEs cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*
Vendors & Products Open5gs
Open5gs open5gs
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-17T02:15:08.258Z

Reserved: 2026-05-16T10:08:49.784Z

Link: CVE-2026-8728

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-17T04:16:58.710

Modified: 2026-05-17T04:16:58.710

Link: CVE-2026-8728

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-17T05:00:09Z

Weaknesses