Executive brief
Open5GS is a core component of 5G mobile networks that manages packet data sessions between user devices and the internet. A vulnerability in the session management component allows a remote attacker to crash the service by sending a specially crafted network request, disrupting mobile network operations and preventing users from accessing data services.
Technical details
A reachable assertion vulnerability exists in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7.6. The vulnerability is triggered in the smf_sess_find_by_psi() function when a DELETE request is sent with an unassigned PDU session identity (psi). The function fails an internal consistency check (assertion) that expects a valid session identifier, causing the SMF daemon to abort. An unauthenticated remote attacker can trigger this crash over the network by crafting a malicious HTTP/2 request to the session management endpoint, leading to Denial of Service. The fix requires patching the assertion handling or request validation logic in the vulnerable function.
Affected products
- Open5GS Open5GS v2.7.6
Timeline
- 2026-08-27: disclosed: CVE-2026-30047 published on NVD