Executive brief
Open5GS is an open-source 5G core network implementation used in telecommunications deployments. An integer overflow vulnerability in the network function repository (NRF) component allows remote attackers to crash the NRF service by sending a specially crafted HTTP/2 request with an oversized numeric parameter, causing complete service unavailability.
Technical details
The vulnerability is an integer overflow in the /nnrf-disc/v1/nf-instances endpoint's parameter parsing logic, specifically in the `ogs_uint64_from_string()` function (in ogs-conv.c:241). When parsing the requester-features parameter, the code attempts to convert a very large numeric string (e.g., "ffffffffffffffffffffffffffffffffffffffff") to a 64-bit unsigned integer without validating bounds, causing `strtoll()` to fail with a numerical result out of range error. The application then triggers a fatal assertion that crashes the NRF process. The vulnerability is reachable remotely via unauthenticated HTTP/2 GET requests and requires no special preconditions. An attacker can achieve denial of service by repeatedly sending malicious requests to crash the NRF, disrupting 5G core network operations.
Affected products
- Open5GS Open5GS v2.7.6
Timeline
- 2026-08-27: disclosed: Vulnerability advisory published
- 2026-01-08: other: Vulnerability reported in GitHub issue #4263