CVE-2026-8119: Open5GS NSSF nghttp2-server.c ogs_sbi_stream_find_by_id denial of service
A vulnerability was detected in Open5GS up to 2.7.7. Impacted is the function ogssbistreamfindbyid in the library /lib/sbi/nghttp2-server.c of the component NSSF. Performing a manipulation results in denial of service. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8119?
CVE-2026-8119 is classified as a denial of service vulnerability in Open5GS NSSF versions up to 2.7.7.
How do I fix CVE-2026-8119?
To fix CVE-2026-8119, upgrade Open5GS NSSF to version 2.8.0 or later.
What components are affected by CVE-2026-8119?
CVE-2026-8119 affects the NSSF component of Open5GS specifically targeting the function ogs_sbi_stream_find_by_id.
What are the potential impacts of CVE-2026-8119?
The potential impact of CVE-2026-8119 includes denial of service, resulting in the disruption of services provided by Open5GS.
How can I identify if I am vulnerable to CVE-2026-8119?
You can identify if you are vulnerable to CVE-2026-8119 by checking if you are running Open5GS NSSF version 2.7.7 or earlier.