Executive brief
Open5GS is an open-source implementation of 5G and LTE core network functions. A security flaw in its Network Repository Function (NRF) component allows a remote attacker to crash the service by timing specific network requests. This results in a denial-of-service, potentially disrupting the ability of mobile network elements to discover and connect to one another.
Technical details
A use-after-free vulnerability exists in the Open5GS NRF component within the discover_handler function of /lib/sbi/nghttp2-server.c. The issue occurs during inter-PLMN discovery when the NRF stores a raw pointer to an HTTP/2 stream. If the original client disconnects before a delayed Home-NRF response arrives, the NRF attempts to reuse the now-freed stream pointer, triggering an assertion failure and service crash. An attacker can exploit this by initiating a discovery request and disconnecting before the response is processed. As of the advisory date, the project has been informed but a formal patch has not been confirmed.
Affected products
- Open5GS Open5GS up to 2.7.7
Timeline
- 2026-04-23: disclosed: Issue reported on GitHub repository
- 2026-05-17: advisory: CVE-2026-8746 published