CVE-2026-8744

A vulnerability was determined in Open5GS up to 2.7.7. Affected is the function ogs_sbi_subscription_data_add/ogs_sbi_nf_service_add in the library /lib/sbi/context.c of the component NRF. Executing a manipulation can lead to denial of service. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. This patch is called 819db11a08b9736a3576c4f99ceb28f7eb99523a. A patch should be applied to remediate this issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*

History

18 May 2026, 18:34

Type Values Removed Values Added
CPE cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*
References () https://github.com/open5gs/open5gs/ - () https://github.com/open5gs/open5gs/ - Product
References () https://github.com/open5gs/open5gs/commit/819db11a08b9736a3576c4f99ceb28f7eb99523a - () https://github.com/open5gs/open5gs/commit/819db11a08b9736a3576c4f99ceb28f7eb99523a - Patch
References () https://github.com/open5gs/open5gs/issues/4465 - () https://github.com/open5gs/open5gs/issues/4465 - Exploit, Issue Tracking
References () https://github.com/open5gs/open5gs/issues/4466 - () https://github.com/open5gs/open5gs/issues/4466 - Exploit, Issue Tracking
References () https://github.com/open5gs/open5gs/pull/4534 - () https://github.com/open5gs/open5gs/pull/4534 - Issue Tracking, Patch
References () https://vuldb.com/submit/817029 - () https://vuldb.com/submit/817029 - Third Party Advisory, VDB Entry
References () https://vuldb.com/submit/817030 - () https://vuldb.com/submit/817030 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/364331 - () https://vuldb.com/vuln/364331 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/364331/cti - () https://vuldb.com/vuln/364331/cti - Permissions Required, VDB Entry
First Time Open5gs
Open5gs open5gs

17 May 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-17 10:16

Updated : 2026-05-18 18:34


NVD link : CVE-2026-8744

Mitre link : CVE-2026-8744

CVE.ORG link : CVE-2026-8744


JSON object : View

Products Affected

open5gs

  • open5gs
CWE
CWE-404

Improper Resource Shutdown or Release