PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8268 Open5gs CVE debrief

CVE-2026-8268 is a denial of service vulnerability in the OpenAPI_list_create function of the SMF component in Open5GS up to 2.7.7. The vulnerability can be exploited remotely. Users of Open5GS should be aware of this issue and take necessary precautions until a patch is available. This includes reviewing system configurations, monitoring for potential exploitation attempts, and planning for an upgrade to a version beyond 2.7.7 when available. The project was informed early through an issue report but has not yet responded with a patch.

Vendor
Open5gs
Product
Open5GS
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-11
Original CVE updated
2026-07-23
Advisory published
2026-05-11
Advisory updated
2026-07-23

Who should care

Users of Open5GS up to version 2.7.7 should be aware of this denial of service vulnerability and take necessary precautions. This includes reviewing system configurations, monitoring for potential exploitation attempts, and planning for an upgrade to a version beyond 2.7.7 when available. Operators, platform administrators, vulnerability management teams, and security teams should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Technical summary

A vulnerability has been found in Open5GS up to 2.7.7 in the OpenAPI_list_create function of the SMF component. This issue leads to denial of service and can be exploited remotely. The project was informed early through an issue report but has not yet responded with a patch. Users should review system configurations, monitor for potential exploitation attempts, and plan for an upgrade to a version beyond 2.7.7 when available.

Defensive priority

Low priority due to CVSS score of 2.1 and lack of immediate response from the vendor. However, users should still take necessary precautions to protect their systems and review compensating controls for exposed systems while remediation is scheduled and verified.

Recommended defensive actions

  • Inventory and verify affected Open5GS installations
  • Apply compensating controls to limit exposure
  • Monitor for potential exploitation attempts
  • Consider upgrading to a version beyond 2.7.7 when available
  • Review system configurations for potential vulnerabilities
  • Track exceptions and retest remediated assets
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

Evidence is based on CVE and NVD records. Detailed information about the vulnerability is limited. Further investigation and verification are recommended. The project was informed early through an issue report but has not responded yet. Open5GS up to 2.7.7 is affected by this vulnerability. Defenders should verify affected scope, severity, and vendor guidance.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-11T04:16:20.403Z and has not been modified since then.