CVE-2026-8291: Open5GS NRF nnrf-handler.c ogs_nnrf_nfm_handle_nf_profile denial of service
A weakness has been identified in Open5GS up to 2.7.7. Impacted is the function ogsnnrfnfmhandlenfprofile of the file lib/sbi/nnrf-handler.c of the component NRF. This manipulation causes denial of service. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The pull request to fix this issue awaits acceptance.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8291?
CVE-2026-8291 has been identified as a denial of service vulnerability in Open5GS versions up to 2.7.7.
How do I fix CVE-2026-8291?
To fix CVE-2026-8291, upgrade Open5GS to the latest version beyond 2.7.7.
What component is affected by CVE-2026-8291?
CVE-2026-8291 affects the NRF component, specifically the function ogs_nnrf_nfm_handle_nf_profile.
What type of attack does CVE-2026-8291 lead to?
CVE-2026-8291 leads to a denial of service attack due to manipulation of the NRF.
Which versions of Open5GS are vulnerable to CVE-2026-8291?
Open5GS versions up to and including 2.7.7 are vulnerable to CVE-2026-8291.