CVE-2026-8251: Open5GS SMF npcf-handler.c update_authorized_pcc_rule_and_qos denial of service
A vulnerability was found in Open5GS up to 2.7.7. This impacts the function updateauthorizedpccruleandqos of the file /src/smf/npcf-handler.c of the component SMF. Performing a manipulation results in denial of service. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8251?
CVE-2026-8251 is classified as a denial of service vulnerability, which can disrupt the availability of the affected service.
How do I fix CVE-2026-8251?
To fix CVE-2026-8251, users should upgrade Open5GS to version 2.7.8 or later, as this version addresses the vulnerability.
What component is affected by CVE-2026-8251?
CVE-2026-8251 affects the SMF component of Open5GS, specifically in the update_authorized_pcc_rule_and_qos function of npcf-handler.c.
Which versions of Open5GS are impacted by CVE-2026-8251?
CVE-2026-8251 impacts all versions of Open5GS up to 2.7.7.
What type of attack is possible with CVE-2026-8251?
CVE-2026-8251 allows for denial of service attacks, which can render the service unavailable to legitimate users.