A vulnerability was detected in Open5GS up to 2.7.7. Impacted is the function ogs_sbi_stream_find_by_id in the library /lib/sbi/nghttp2-server.c of the component NSSF. Performing a manipulation results in denial of service. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
References
| Link | Resource |
|---|---|
| https://github.com/open5gs/open5gs/ | Product |
| https://github.com/open5gs/open5gs/issues/4431 | Exploit Issue Tracking |
| https://vuldb.com/submit/808420 | Third Party Advisory VDB Entry Exploit |
| https://vuldb.com/vuln/361906 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/361906/cti | Permissions Required VDB Entry |
Configurations
History
11 May 2026, 14:29
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/open5gs/open5gs/ - Product | |
| References | () https://github.com/open5gs/open5gs/issues/4431 - Exploit, Issue Tracking | |
| References | () https://vuldb.com/submit/808420 - Third Party Advisory, VDB Entry, Exploit | |
| References | () https://vuldb.com/vuln/361906 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/361906/cti - Permissions Required, VDB Entry | |
| CPE | cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:* | |
| First Time |
Open5gs
Open5gs open5gs |
08 May 2026, 01:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-08 01:16
Updated : 2026-05-11 14:29
NVD link : CVE-2026-8119
Mitre link : CVE-2026-8119
CVE.ORG link : CVE-2026-8119
JSON object : View
Products Affected
open5gs
- open5gs
CWE
CWE-404
Improper Resource Shutdown or Release
