CVE-2026-7536: Open5GS BSF pcfBindings bsf_sess_add_by_ip_address denial of service
A vulnerability was determined in Open5GS up to 2.7.7. This vulnerability affects the function bsfsessaddbyipaddress of the file /nbsf-management/v1/pcfBindings of the component BSF. Executing a manipulation of the argument ipv4Addr can lead to denial of service. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7536?
CVE-2026-7536 is classified as a denial of service vulnerability that can disrupt the availability of the Open5GS BSF component.
How does CVE-2026-7536 affect Open5GS?
CVE-2026-7536 affects the bsf_sess_add_by_ip_address function within Open5GS, allowing for potential denial of service through argument manipulation.
How can I fix CVE-2026-7536?
To fix CVE-2026-7536, update Open5GS to a version later than 2.7.7 where the vulnerability has been addressed.
What components are impacted by CVE-2026-7536?
CVE-2026-7536 specifically impacts the BSF component of Open5GS, particularly the pcfBindings functionality.
What versions of Open5GS are affected by CVE-2026-7536?
CVE-2026-7536 affects Open5GS versions up to and including 2.7.7.