CVE-2026-71675: Open5gs open5gs vulnerability
Published Aug 18, 2026
·Updated
An issue in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the ngapsendtonas() function in src/amf/ngap-path.c
Affected Software
1 affected component
open5gs open5gs=2.7.0
Event History
Aug 18, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which deployments should be checked first?
The affected software is Open5GS version 2.7.0. The available information identifies the issue in the AMF NGAP code path, specifically ngap_send_to_nas() in src/amf/ngap-path.c.
2
What attacker access or prerequisites are known?
The issue is described as remotely exploitable and can cause denial of service. The provided information does not specify authentication requirements, network position, or the precise malformed input needed.
3
Are configuration-based mitigations or a patched release identified?
The available information does not state whether default configurations are affected, whether a fixed version exists, or which mitigations are effective when patching cannot occur immediately.