CVE-2026-8270: Open5GS SMF ogs_nas_parse_qos_rules denial of service
A vulnerability was determined in Open5GS up to 2.7.7. The affected element is the function ogsnasparseqosrules of the component SMF. Executing a manipulation can lead to denial of service. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8270?
CVE-2026-8270 has a high severity due to its potential to cause denial of service.
How do I fix CVE-2026-8270?
To fix CVE-2026-8270, upgrade to a version of Open5GS SMF above 2.7.7 where the vulnerability is addressed.
What component is affected by CVE-2026-8270?
CVE-2026-8270 affects the ogs_nas_parse_qos_rules function within the SMF component of Open5GS.
Can CVE-2026-8270 be exploited remotely?
Yes, CVE-2026-8270 can be exploited remotely, leading to denial of service.
Which versions of Open5GS are vulnerable to CVE-2026-8270?
Open5GS versions up to and including 2.7.7 are vulnerable to CVE-2026-8270.