Open5GS AUSF Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in Open5GS versions prior to 2.7.7, specifically within the AUSF component. The issue arises in the 'ogs_timer_add' function of the 'nausf-handler.c' library. This vulnerability allows for remote exploitation, where an attacker can exhaust the timer pool by sending repeated confirmation requests, causing the AUSF to crash. The vulnerability has been publicly disclosed and is available for exploitation.

Impact

Exploitation of this vulnerability leads to a crash of the AUSF component, causing it to exit with a code indicating a segmentation fault.

Reproduction

The vulnerability can be reproduced by creating a valid authentication context and then sending repeated 'PUT' requests to the '/nausf-auth/v1/ue-authentications/{authCtxId}/5g-aka-confirmation' endpoint. This should be done while keeping the UDM's 'POST /nudm-ueau/v1/{supi}/auth-events' endpoint hanging, which allows the confirmation requests to accumulate and exhaust the timer pool, causing AUSF to crash.

Added: May 17, 2026, 10:20 AM
Updated: May 17, 2026, 10:20 AM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
5.8
remediation
0.0
relevance
8.6
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.