A weakness has been identified in Open5GS up to 2.7.7. The affected element is the function smf_nudm_sdm_handle_get of the file src/smf/nudm-handler.c of the component SMF. Executing a manipulation of the argument preemptCap can lead to reachable assertion. The attack may be launched remotely. Upgrading to version 2.8.0 is sufficient to fix this issue. This patch is called 4554405f29bffd7562abedbee63484825bd90cd5. You should upgrade the affected component.
https://vuldb.com/vuln/397085/cti
https://vuldb.com/submit/891893
https://vuldb.com/cve/CVE-2026-82590
https://github.com/open5gs/open5gs/releases/tag/v2.8.0
https://github.com/open5gs/open5gs/issues/4455
https://github.com/open5gs/open5gs/commit/4554405f29bffd7562abedbee63484825bd90cd5
Published: 2026-08-30
Updated: 2026-08-30
Base Score: 4
Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:N/A:P
Severity: Medium
Base Score: 4.3
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Severity: Medium
Base Score: 5.3
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Severity: Medium