CVE-2026-10115
4.3 MEDIUMA vulnerability was identified in Open5GS up to 2.7.7
Published: 2026-05-30 · Last updated: 2026-06-03
Severity and scoring
- CVSS
- 4.3 MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- CWE
- CWE-404
Description
A vulnerability was identified in Open5GS up to 2.7.7. This affects an unknown part in the library lib/sbi/nnrf-handler.c of the component Shared NF-profile Parser. Such manipulation leads to denial of service. The attack can be launched remotely. The exploit is publicly available and might be used. It is advisable to implement a patch to correct this issue.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-10115
- [Other]https://github.com/open5gs/open5gs/
- [Other]https://github.com/open5gs/open5gs/issues/4469
- [Other]https://github.com/open5gs/open5gs/issues/4469#issuecomment-4389805398
- [Other]https://github.com/open5gs/open5gs/pull/4527
- [Other]https://vuldb.com/submit/818583
- [Other]https://vuldb.com/vuln/367293
- [Other]https://vuldb.com/vuln/367293/cti
- [Other]https://github.com/open5gs/open5gs/issues/4469#issuecomment-4389805398
- [Other]https://github.com/open5gs/open5gs/pull/4527
- [Other]https://vuldb.com/submit/818583
Related CVEs
Same CWE
- CVE-2026-45174 — Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon ini...
- CVE-2026-47213 — Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to ru... (6.5 MEDIUM)
- CVE-2026-11312 — A vulnerability was found in bytedance InfiniStore up to 0.2.33 (3.3 LOW)
- CVE-2026-10802 — A vulnerability was detected in keystonejs keystone up to 20260319 (4.3 MEDIUM)
- CVE-2026-10775 — A vulnerability was determined in sgl-project SGLang up to 0.5.11 (3.6 LOW)