CVE-2026-10156: Open5GS nf-instances Endpoint nnrf-handler.c handle_amf_info resource consumption
A vulnerability was determined in Open5GS up to 2.7.7. This affects the function handleamfinfo in the library /lib/sbi/nnrf-handler.c of the component nf-instances Endpoint. Executing a manipulation of the argument nfinfopool can lead to resource consumption. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Applying a patch is advised to resolve this issue. The issue report is flagged as already-fixed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Open5GSto a version that resolves this vulnerability.Fixed in 2.7.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10156?
The severity of CVE-2026-10156 is rated medium with a score of 4.3.
How do I fix CVE-2026-10156?
To fix CVE-2026-10156, upgrade Open5GS to version 2.7.8 or later where the vulnerability has been addressed.
What components are affected by CVE-2026-10156?
CVE-2026-10156 affects the nf-instances Endpoint, specifically the handle_amf_info function in nnrf-handler.c.
What type of attack does CVE-2026-10156 facilitate?
CVE-2026-10156 facilitates a resource consumption attack that can be executed through manipulation of the nf_info_pool argument.
What is the potential impact of exploiting CVE-2026-10156?
Exploiting CVE-2026-10156 can lead to denial of service due to resource exhaustion in the affected system.