CVE-2026-30047: High severity open5gs open5gs vulnerability
Published Aug 27, 2026
·Updated
A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.
Affected Software
1 affected component
open5gs open5gs=2.7.6
Event History
Aug 27, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to do to trigger the denial of service?
The attacker must be able to send a crafted DELETE request to the reachable /nsmf-pdusession/v1/sm-contexts component.
2
Which deployment is identified as affected?
The provided information identifies Open5GS v2.7.6 as affected. It does not state whether other versions or default configurations are affected.