Open5GS Denial-of-Service Vulnerability in UDM Component AMF Registration Update Handling

Vulnerability

A denial-of-service vulnerability has been identified in Open5GS versions prior to 2.7.7. The issue arises in the User Data Management (UDM) component, specifically within the 3GPP access registration update handling function. When a request is received with the purge flag set to true, but no corresponding AMF registration state exists, the UDM process crashes. This vulnerability can be exploited remotely, leading to a process termination and potential service disruption.

Impact

Exploitation of this vulnerability causes the UDM process to crash, terminating the process and potentially disrupting services that rely on UDM functionality.

Reproduction

To reproduce this vulnerability, send a PATCH request to the UDM endpoint for AMF 3GPP access registrations, including the purge flag set to true. If no AMF registration object exists for the specified user, the UDM process will crash, hitting an assertion failure that causes the process to abort.

Added: May 4, 2026, 11:17 PM
Updated: May 4, 2026, 11:17 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
6.2
remediation
0.0
relevance
7.5
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.