Junglewise Threat Intelligence

CVE-2026-30047: Open5GS reachable assertion in SM context handling

CVE-2026-30047 · Severity: high · CVSS 7.5 · Published 2026-08-27

Technologies: Open5GS. Vendors: Open5GS.

Executive brief

Open5GS is a core component of 5G mobile networks that manages packet data sessions between user devices and the internet. A vulnerability in the session management component allows a remote attacker to crash the service by sending a specially crafted network request, disrupting mobile network operations and preventing users from accessing data services.

Technical details

A reachable assertion vulnerability exists in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7.6. The vulnerability is triggered in the smf_sess_find_by_psi() function when a DELETE request is sent with an unassigned PDU session identity (psi). The function fails an internal consistency check (assertion) that expects a valid session identifier, causing the SMF daemon to abort. An unauthenticated remote attacker can trigger this crash over the network by crafting a malicious HTTP/2 request to the session management endpoint, leading to Denial of Service. The fix requires patching the assertion handling or request validation logic in the vulnerable function.

Affected products

  • Open5GS Open5GS v2.7.6

Timeline

  • 2026-08-27: disclosed: CVE-2026-30047 published on NVD

References

Related threats