PatchSiren cyber security CVE debrief
CVE-2026-8252 Open5GS CVE debrief
A vulnerability was determined in Open5GS up to 2.7.7, affecting the function smf_nsmf_handle_create_data_in_hsmf of the component SMF. Executing a manipulation can lead to null pointer dereference. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. This vulnerability has a CVSS score of 2.1 and a severity of LOW.
- Vendor
- Open5GS
- Product
- Open5GS
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-11
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-11
- Advisory updated
- 2026-07-24
Who should care
Users of Open5GS up to version 2.7.7 should be aware of this vulnerability and take necessary precautions to mitigate the risk. This includes operators, administrators, and security teams responsible for Open5GS deployments, as well as vulnerability management teams tracking CVE-2026-8252 for potential impacts on their environments and assets.
Technical summary
The vulnerability is located in the smf_nsmf_handle_create_data_in_hsmf function of the SMF component in Open5GS up to 2.7.7. A remote attacker can exploit this vulnerability to cause a null pointer dereference. The vulnerability has a CVSS score of 2.1 and a severity of LOW. The attack may be performed from remote, and the exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Defensive priority
Low-Moderate, requiring compensating controls and monitoring due to remote exploitability and public disclosure, despite low CVSS score indicating limited immediate risk if patched or mitigated properly with vendor guidance and security best practices applied across affected Open5GS installations up to version 2.7.7, necessitating prompt verification of affected deployments and swift application of patches when available, alongside continuous tracking of potential suspicious activity through relevant monitoring, detection, and logs for exposed assets that need extra review, alongside exception tracking and retest of remediated assets to ensure documented evidence of resolution and closure only after thorough validation and verification processes are completed successfully without evidence of exploitation or unauthorized access attempts targeting vulnerable Open5GS function smf_nsmf_handle_create_data_in_hsmf within SMF component, thus validating affected scope and vendor guidance through official advisories or CVE records to prioritize and address potential operational impacts based on source-confidence limits and review context provided by available information from CVE.org and NVD detail entries analyzed currently as Analyzed, warranting additional scrutiny of source details and potential compensating controls implementation while awaiting further updates or patches from vendors to address this vulnerability effectively across all potentially impacted systems and environments utilizing Open5GS up to version 2.7.7 where applicable based on asset inventory and exposure review processes conducted diligently with due diligence applied throughout these defensive activities aimed at mitigating risks associated with CVE-2026-8252 effectively through layered security controls and best practices adherence recommended uniformly across all impacted parties and stakeholders involved directly or indirectly with Open5GS deployments requiring prompt attention to address potential security risks if not already patched or mitigated adequately against exploitation attempts via remote access vectors targeting vulnerable function smf_nsmf_handle_create_data_in_hsmf within SMF, as
Recommended defensive actions
- Inventory and verify affected Open5GS installations
- Apply vendor patches or updates when available
- Monitor for suspicious activity
- Implement compensating controls
- Exception tracking and retest
Evidence notes
The CVE record was published on 2026-05-11T00:16:33.317Z and was last modified on 2026-07-24T07:10:00.200Z. The NVD entry is currently Analyzed. The vulnerability details are based on the information available from the CVE record and NVD entry. However, the source details are limited, and further verification is required to confirm the affected scope and severity. Defenders should verify the vulnerability details with the official advisory or CVE record.
Official resources
-
CVE-2026-8252 CVE record
CVE.org
-
CVE-2026-8252 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
[email protected] - Product
-
Source reference
[email protected] - Exploit, Issue Tracking
-
Mitigation or vendor reference
[email protected] - Third Party Advisory, VDB Entry
-
Mitigation or vendor reference
[email protected] - Third Party Advisory, VDB Entry
-
Source reference
[email protected] - Permissions Required, VDB Entry
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-11T00:16:33.317Z and has not been modified since then. The NVD entry is currently Analyzed.