Open5GS Shared NF-Profile Parser Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in Open5GS versions through 2.7.7. The issue arises in the shared NF-profile parser within the file lib/sbi/nnrf-handler.c. When the 'tacRangeList' contains more entries than the parser can handle, it causes an assertion failure, leading to a crash. This vulnerability can be exploited remotely, and the crash occurs in the Network Function (NF) Repository Function (NRF), but the affected parser is used by multiple network functions.

Impact

Exploiting this vulnerability causes the Open5GS process to crash, terminating the HTTP/2 stream and exiting with a code indicating a segmentation fault.

Reproduction

The vulnerability can be reproduced by sending a PUT request to the NRF with an NF instance that includes an oversized 'tacRangeList'. This can be done using a crafted payload that exceeds the internal limits, which will trigger the assertion failure and crash the process.

Remediation

Users are advised to update to the patched version of Open5GS, which is available in the official repository.

Added: May 30, 2026, 9:18 AM
Updated: May 30, 2026, 9:18 AM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
9.1
remediation
0.0
relevance
9.8
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.