PatchSiren cyber security CVE debrief
CVE-2026-8268 Open5gs CVE debrief
CVE-2026-8268 is a denial of service vulnerability in the OpenAPI_list_create function of the SMF component in Open5GS up to 2.7.7. The vulnerability can be exploited remotely. Users of Open5GS should be aware of this issue and take necessary precautions until a patch is available. This includes reviewing system configurations, monitoring for potential exploitation attempts, and planning for an upgrade to a version beyond 2.7.7 when available. The project was informed early through an issue report but has not yet responded with a patch.
- Vendor
- Open5gs
- Product
- Open5GS
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-11
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-11
- Advisory updated
- 2026-07-23
Who should care
Users of Open5GS up to version 2.7.7 should be aware of this denial of service vulnerability and take necessary precautions. This includes reviewing system configurations, monitoring for potential exploitation attempts, and planning for an upgrade to a version beyond 2.7.7 when available. Operators, platform administrators, vulnerability management teams, and security teams should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Technical summary
A vulnerability has been found in Open5GS up to 2.7.7 in the OpenAPI_list_create function of the SMF component. This issue leads to denial of service and can be exploited remotely. The project was informed early through an issue report but has not yet responded with a patch. Users should review system configurations, monitor for potential exploitation attempts, and plan for an upgrade to a version beyond 2.7.7 when available.
Defensive priority
Low priority due to CVSS score of 2.1 and lack of immediate response from the vendor. However, users should still take necessary precautions to protect their systems and review compensating controls for exposed systems while remediation is scheduled and verified.
Recommended defensive actions
- Inventory and verify affected Open5GS installations
- Apply compensating controls to limit exposure
- Monitor for potential exploitation attempts
- Consider upgrading to a version beyond 2.7.7 when available
- Review system configurations for potential vulnerabilities
- Track exceptions and retest remediated assets
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
Evidence is based on CVE and NVD records. Detailed information about the vulnerability is limited. Further investigation and verification are recommended. The project was informed early through an issue report but has not responded yet. Open5GS up to 2.7.7 is affected by this vulnerability. Defenders should verify affected scope, severity, and vendor guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8268 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8268
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8268 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8268
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/open5gs/open5gs/
[email protected] - Product
-
Source reference
Unverified legacy reference
URL: https://github.com/open5gs/open5gs/issues/4449
[email protected] - Exploit, Issue Tracking
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://vuldb.com/submit/808485
[email protected] - Third Party Advisory, VDB Entry
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://vuldb.com/vuln/362565
[email protected] - Third Party Advisory, VDB Entry
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/362565/cti
[email protected] - Permissions Required, VDB Entry
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.