---
id: CVE-2025-15686
title: A vulnerability has been found in Open5GS up to 2.7.6
summary: >-
  A vulnerability has been found in Open5GS up to 2.7.6. Affected by this issue
  is the function fd_msg_sess_get of the component HSS Service. Such
  manipulation of the argument Session-Id leads to denial of service. The attack
  may be perfor…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-404
published: '2026-08-12'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T11:10:00.150'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15686'
references:
  - url: 'https://github.com/open5gs/open5gs/'
    label: cna@vuldb.com
  - url: 'https://github.com/open5gs/open5gs/issues/4190'
    label: cna@vuldb.com
  - url: >-
      https://github.com/user-attachments/files/23847497/HSS_ULR_error_poc.pcapng.zip
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2025-15686'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/867104'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/387279'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/387279/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-09-29T11:32:41.233Z'
---

## Overview

A vulnerability has been found in Open5GS up to 2.7.6. Affected by this issue is the function fd_msg_sess_get of the component HSS Service. Such manipulation of the argument Session-Id leads to denial of service. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project locked and limited conversation to collaborators.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
