A vulnerability was detected in Open5GS up to 2.7.7. Impacted is the function ogs_sbi_stream_find_by_id in the library /lib/sbi/nghttp2-server.c of the component NSSF. Performing a manipulation results in denial of service. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
References
| Link | Resource |
|---|---|
| https://github.com/open5gs/open5gs/ | Product |
| https://github.com/open5gs/open5gs/issues/4431 | Exploit Issue Tracking |
| https://vuldb.com/submit/808420 | Exploit Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/361906 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/361906/cti | Permissions Required VDB Entry |
Configurations
History
No history.
Information
Published : 2026-05-08 01:16
Updated : 2026-06-17 11:03
NVD link : CVE-2026-8119
Mitre link : CVE-2026-8119
CVE.ORG link : CVE-2026-8119
JSON object : View
Products Affected
open5gs
- open5gs
CWE
CWE-404
Improper Resource Shutdown or Release
