CVE-2026-8250: Open5GS SMF n4-build.c smf_n4_build_qos_flow_to_modify_list denial of service
A vulnerability has been found in Open5GS up to 2.7.7. This affects the function smfn4buildqosflowtomodifylist of the file /src/smf/n4-build.c of the component SMF. Such manipulation leads to denial of service. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8250?
CVE-2026-8250 is classified as a denial of service vulnerability.
How do I fix CVE-2026-8250?
To resolve CVE-2026-8250, upgrade Open5GS to a version later than 2.7.7.
Which versions of Open5GS are affected by CVE-2026-8250?
Open5GS versions up to and including 2.7.7 are affected by CVE-2026-8250.
What component of Open5GS does CVE-2026-8250 impact?
CVE-2026-8250 impacts the SMF component of Open5GS.
What function is vulnerable in CVE-2026-8250?
The vulnerability in CVE-2026-8250 is found in the function smf_n4_build_qos_flow_to_modify_list.