Junglewise Threat Intelligence

CVE-2026-8267: Open5GS SMF denial of service in smf_nsmf_handle_created_data_in_vsmf

CVE-2026-8267 · Severity: medium · CVSS 4.3 · Published 2026-05-11

Technologies: Open5GS. Vendors: Open5GS.

Executive brief

Open5GS is an open-source implementation of 5G Core and EPC network functions used in mobile telecommunications. A flaw in the Session Management Function (SMF) component allows a remote attacker to crash the service, leading to a denial of service. This could disrupt mobile network connectivity and session management for connected users.

Technical details

A denial of service vulnerability exists in Open5GS up to version 2.7.7 within the Session Management Function (SMF) component. The flaw is located in the smf_nsmf_handle_created_data_in_vsmf function and is triggered when the SMF receives a '201 Created' response from an H-SMF that is missing the 'hcnTunnelInfo' field. This improper resource handling (CWE-404) leads to a service crash. The attack can be initiated remotely by an authenticated user or adjacent network function. While the project was notified via an issue report, a formal patch version has not been explicitly confirmed in the advisory, though the issue is marked as 'already-fixed' in the repository tracking.

Affected products

  • Open5GS Open5GS up to 2.7.7

Timeline

  • 2026-05-11: advisory: Initial disclosure by VulDB
  • 2026-05-11: disclosed: Exploit code published publicly

References

Related threats