{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/open5gs--2.7.x/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.3,"id":"CVE-2026-90707"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Open5GS (\u003c= 2.7.x)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","open5gs","cve"],"_cs_type":"advisory","_cs_vendors":["Open5GS"],"content_html":"\u003cp\u003eA critical use-after-free vulnerability, tracked as CVE-2026-90707, exists in Open5GS versions up to 2.7.x. The issue resides within the 'amf_nnrf_try_old_amf_discovery_fallback' function located in 'src/amf/nnrf-handler.c'. An attacker can remotely exploit this flaw by providing a crafted 'discovery_option' argument to the NNRF (Non-3GPP Interworking Function) handler. This manipulation causes the application to access memory after it has been freed, which may lead to application crashes or potentially arbitrary code execution in the context of the Open5GS service. Security teams should prioritize patching this component, as the Open5GS service acts as a core node in 5G network infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability could result in a denial of service (DoS) through application process termination or, in more complex scenarios, arbitrary code execution on the underlying server. Because Open5GS is a critical component in 5G core networks, a service outage could disrupt network connectivity for connected users.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Open5GS installations to a version containing the fix identified by commit hash 'ddd683a35f8aaac2b7b9884a24cd53bddfc65238'.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic logs for anomalous NNRF API requests involving unexpected or overly long 'discovery_option' values that target the AMF component.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation to isolate the Open5GS AMF service from untrusted or external networks to limit the attack surface for remote exploitation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-14T11:33:15Z","date_published":"2026-09-14T11:33:15Z","id":"https://feed.craftedsignal.io/briefs/2026-09-open5gs-uaf/","summary":"A use-after-free vulnerability in the Open5GS AMF component allows remote attackers to trigger memory corruption via manipulated discovery options, potentially leading to service disruption or code execution.","title":"Remote Use-After-Free Vulnerability in Open5GS","url":"https://feed.craftedsignal.io/briefs/2026-09-open5gs-uaf/"}],"language":"en","title":"CraftedSignal Threat Feed - Open5GS (\u003c= 2.7.x)","version":"https://jsonfeed.org/version/1.1"}