CVE-2025-15532

A security flaw has been discovered in Open5GS up to 2.7.5. This issue affects some unknown processing of the component Timer Handler. The manipulation results in resource consumption. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The patch is identified as c7c131f8d2cb1195ada5e0e691b6868ebcd8a845. It is best practice to apply a patch to resolve this issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*

History

23 Feb 2026, 09:16

Type Values Removed Values Added
References
  • () https://github.com/open5gs/open5gs/ -
  • () https://vuldb.com/?submit.735340 -
  • () https://vuldb.com/?submit.735341 -
  • () https://vuldb.com/?submit.735342 -

09 Feb 2026, 20:28

Type Values Removed Values Added
CPE cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*
First Time Open5gs open5gs
Open5gs
References () https://github.com/open5gs/open5gs/commit/c7c131f8d2cb1195ada5e0e691b6868ebcd8a845 - () https://github.com/open5gs/open5gs/commit/c7c131f8d2cb1195ada5e0e691b6868ebcd8a845 - Patch
References () https://github.com/open5gs/open5gs/issues/4220 - () https://github.com/open5gs/open5gs/issues/4220 - Exploit, Issue Tracking, Vendor Advisory
References () https://github.com/open5gs/open5gs/issues/4220#issue-3766066853 - () https://github.com/open5gs/open5gs/issues/4220#issue-3766066853 - Exploit, Issue Tracking, Vendor Advisory
References () https://github.com/open5gs/open5gs/issues/4221 - () https://github.com/open5gs/open5gs/issues/4221 - Exploit, Issue Tracking, Vendor Advisory
References () https://vuldb.com/?ctiid.341599 - () https://vuldb.com/?ctiid.341599 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.341599 - () https://vuldb.com/?id.341599 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.729354 - () https://vuldb.com/?submit.729354 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.729357 - () https://vuldb.com/?submit.729357 - Third Party Advisory, VDB Entry

17 Jan 2026, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-17 17:15

Updated : 2026-02-23 09:16


NVD link : CVE-2025-15532

Mitre link : CVE-2025-15532

CVE.ORG link : CVE-2025-15532


JSON object : View

Products Affected

open5gs

  • open5gs
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-404

Improper Resource Shutdown or Release