CVE-2026-82588

medium

Description

A vulnerability was identified in Open5GS up to 2.7.7. This issue affects some unknown processing of the file src/amf/namf-handler.c of the component Transfer Endpoint. Such manipulation leads to null pointer dereference. The attack can be launched remotely. Upgrading to version 2.8.0 is capable of addressing this issue. The name of the patch is abf8a836564b966b5141110fc25ed413c4f17522. Upgrading the affected component is advised.

References

https://vuldb.com/vuln/397083/cti

https://vuldb.com/vuln/397083

https://vuldb.com/submit/891891

https://vuldb.com/cve/CVE-2026-82588

https://github.com/open5gs/open5gs/releases/tag/v2.8.0

https://github.com/open5gs/open5gs/issues/4397

https://github.com/open5gs/open5gs/commit/abf8a836564b966b5141110fc25ed413c4f17522

https://github.com/open5gs/open5gs/

Details

Source: Mitre, NVD

Published: 2026-08-30

Updated: 2026-08-30

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Severity: Medium

CVSS v4

Base Score: 5.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Severity: Medium