CVE-2026-30045: Integer Overflow
Published Aug 27, 2026
·Updated
An integer overflow in the /nnrf-disc/v1/nf-instances component of open5gs v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted HTTP/2 GET request.
Affected Software
1 affected component
open5gs open5gs=2.7.6
Event History
Aug 27, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:17 PM
Description
Frequently Asked Questions
1
Which deployments are exposed to this denial-of-service issue?
Open5GS v2.7.6 deployments that expose the /nnrf-disc/v1/nf-instances component and accept HTTP/2 GET requests to that endpoint are affected.
2
What does an attacker need to exploit the issue?
An attacker needs to be able to supply a crafted HTTP/2 GET request to the vulnerable endpoint. The provided information does not state that authentication or prior access is required.
3
What is the impact of successful exploitation?
Successful exploitation can cause a denial of service in the affected Open5GS component.