PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8252 Open5GS CVE debrief

A vulnerability was determined in Open5GS up to 2.7.7, affecting the function smf_nsmf_handle_create_data_in_hsmf of the component SMF. Executing a manipulation can lead to null pointer dereference. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. This vulnerability has a CVSS score of 2.1 and a severity of LOW.

Vendor
Open5GS
Product
Open5GS
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-11
Original CVE updated
2026-07-24
Advisory published
2026-05-11
Advisory updated
2026-07-24

Who should care

Users of Open5GS up to version 2.7.7 should be aware of this vulnerability and take necessary precautions to mitigate the risk. This includes operators, administrators, and security teams responsible for Open5GS deployments, as well as vulnerability management teams tracking CVE-2026-8252 for potential impacts on their environments and assets.

Technical summary

The vulnerability is located in the smf_nsmf_handle_create_data_in_hsmf function of the SMF component in Open5GS up to 2.7.7. A remote attacker can exploit this vulnerability to cause a null pointer dereference. The vulnerability has a CVSS score of 2.1 and a severity of LOW. The attack may be performed from remote, and the exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

Defensive priority

Low-Moderate, requiring compensating controls and monitoring due to remote exploitability and public disclosure, despite low CVSS score indicating limited immediate risk if patched or mitigated properly with vendor guidance and security best practices applied across affected Open5GS installations up to version 2.7.7, necessitating prompt verification of affected deployments and swift application of patches when available, alongside continuous tracking of potential suspicious activity through relevant monitoring, detection, and logs for exposed assets that need extra review, alongside exception tracking and retest of remediated assets to ensure documented evidence of resolution and closure only after thorough validation and verification processes are completed successfully without evidence of exploitation or unauthorized access attempts targeting vulnerable Open5GS function smf_nsmf_handle_create_data_in_hsmf within SMF component, thus validating affected scope and vendor guidance through official advisories or CVE records to prioritize and address potential operational impacts based on source-confidence limits and review context provided by available information from CVE.org and NVD detail entries analyzed currently as Analyzed, warranting additional scrutiny of source details and potential compensating controls implementation while awaiting further updates or patches from vendors to address this vulnerability effectively across all potentially impacted systems and environments utilizing Open5GS up to version 2.7.7 where applicable based on asset inventory and exposure review processes conducted diligently with due diligence applied throughout these defensive activities aimed at mitigating risks associated with CVE-2026-8252 effectively through layered security controls and best practices adherence recommended uniformly across all impacted parties and stakeholders involved directly or indirectly with Open5GS deployments requiring prompt attention to address potential security risks if not already patched or mitigated adequately against exploitation attempts via remote access vectors targeting vulnerable function smf_nsmf_handle_create_data_in_hsmf within SMF, as

Recommended defensive actions

  • Inventory and verify affected Open5GS installations
  • Apply vendor patches or updates when available
  • Monitor for suspicious activity
  • Implement compensating controls
  • Exception tracking and retest

Evidence notes

The CVE record was published on 2026-05-11T00:16:33.317Z and was last modified on 2026-07-24T07:10:00.200Z. The NVD entry is currently Analyzed. The vulnerability details are based on the information available from the CVE record and NVD entry. However, the source details are limited, and further verification is required to confirm the affected scope and severity. Defenders should verify the vulnerability details with the official advisory or CVE record.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-11T00:16:33.317Z and has not been modified since then. The NVD entry is currently Analyzed.