Junglewise Threat Intelligence

CVE-2026-30045: Open5GS integer overflow in /nnrf-disc/v1/nf-instances

CVE-2026-30045 · Severity: high · CVSS 7.5 · Published 2026-08-27

Technologies: Open5GS. Vendors: Open5GS.

Executive brief

Open5GS is an open-source 5G core network implementation used in telecommunications deployments. An integer overflow vulnerability in the network function repository (NRF) component allows remote attackers to crash the NRF service by sending a specially crafted HTTP/2 request with an oversized numeric parameter, causing complete service unavailability.

Technical details

The vulnerability is an integer overflow in the /nnrf-disc/v1/nf-instances endpoint's parameter parsing logic, specifically in the `ogs_uint64_from_string()` function (in ogs-conv.c:241). When parsing the requester-features parameter, the code attempts to convert a very large numeric string (e.g., "ffffffffffffffffffffffffffffffffffffffff") to a 64-bit unsigned integer without validating bounds, causing `strtoll()` to fail with a numerical result out of range error. The application then triggers a fatal assertion that crashes the NRF process. The vulnerability is reachable remotely via unauthenticated HTTP/2 GET requests and requires no special preconditions. An attacker can achieve denial of service by repeatedly sending malicious requests to crash the NRF, disrupting 5G core network operations.

Affected products

  • Open5GS Open5GS v2.7.6

Timeline

  • 2026-08-27: disclosed: Vulnerability advisory published
  • 2026-01-08: other: Vulnerability reported in GitHub issue #4263

References

Related threats