CVE-2026-8289: Open5GS SMF nsmf-handler.c smf_nsmf_handle_update_data_in_vsmf denial of service
A vulnerability was identified in Open5GS up to 2.7.7. This vulnerability affects the function smfnsmfhandleupdatedatainvsmf of the file /src/smf/nsmf-handler.c of the component SMF. The manipulation of the argument qosFlowProfile leads to denial of service. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8289?
CVE-2026-8289 is classified as a denial of service vulnerability.
How do I fix CVE-2026-8289?
To fix CVE-2026-8289, upgrade Open5GS SMF to version 2.7.8 or later.
Which versions of Open5GS SMF are affected by CVE-2026-8289?
Open5GS SMF versions up to and including 2.7.7 are affected by CVE-2026-8289.
What component of Open5GS is impacted by CVE-2026-8289?
The vulnerability CVE-2026-8289 impacts the SMF component of Open5GS.
What specific function in Open5GS SMF is associated with CVE-2026-8289?
CVE-2026-8289 is associated with the function smf_nsmf_handle_update_data_in_vsmf in nsmf-handler.c.