Open5GS Denial-of-Service Vulnerability in NRF Component

Vulnerability

A denial-of-service vulnerability has been identified in Open5GS versions through 2.7.7, specifically within the NRF component. The issue arises in the function yuarel_parse, located in the library /lib/sbi/conv.c. When an invalid 'hnrf-uri' is provided, it leads to a null dereference, causing the NRF process to crash. This vulnerability can be exploited remotely.

Impact

Exploitation of this vulnerability causes the NRF process to terminate unexpectedly, leading to a crash.

Reproduction

The vulnerability can be reproduced by sending a GET request to the '/nnrf-disc/v1/nf-instances' endpoint with an invalid 'hnrf-uri' parameter, along with 'target-plmn-list' and 'requester-plmn-list' parameters. The NRF process will then crash due to a null dereference.

Added: May 11, 2026, 4:21 PM
Updated: May 11, 2026, 4:21 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
9.1
remediation
0.0
relevance
8.0
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.