Junglewise Threat Intelligence

CVE-2026-8746: Open5GS use after free in NRF discover_handler

CVE-2026-8746 · Severity: medium · CVSS 4.3 · Published 2026-05-17

Technologies: Open5GS. Vendors: Open5GS.

Executive brief

Open5GS is an open-source implementation of 5G and LTE core network functions. A security flaw in its Network Repository Function (NRF) component allows a remote attacker to crash the service by timing specific network requests. This results in a denial-of-service, potentially disrupting the ability of mobile network elements to discover and connect to one another.

Technical details

A use-after-free vulnerability exists in the Open5GS NRF component within the discover_handler function of /lib/sbi/nghttp2-server.c. The issue occurs during inter-PLMN discovery when the NRF stores a raw pointer to an HTTP/2 stream. If the original client disconnects before a delayed Home-NRF response arrives, the NRF attempts to reuse the now-freed stream pointer, triggering an assertion failure and service crash. An attacker can exploit this by initiating a discovery request and disconnecting before the response is processed. As of the advisory date, the project has been informed but a formal patch has not been confirmed.

Affected products

  • Open5GS Open5GS up to 2.7.7

Timeline

  • 2026-04-23: disclosed: Issue reported on GitHub repository
  • 2026-05-17: advisory: CVE-2026-8746 published

References

Related threats