---
id: CVE-2026-8225
title: A vulnerability was identified in Open5GS up to 2.7.7
summary: >-
  A vulnerability was identified in Open5GS up to 2.7.7. This affects the
  function pcf_npcf_smpolicycontrol_handle_delete of the file src/pcf/sm-sm.c of
  the component delete Endpoint. The manipulation leads to denial of service.
  The attack…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-404
vendor: open5gs
product: open5gs
affected:
  - open5gs <= 2.7.7
published: '2026-05-10'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-8225'
references:
  - url: 'https://github.com/open5gs/open5gs/'
    label: cna@vuldb.com
  - url: 'https://github.com/open5gs/open5gs/issues/4440'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/808444'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/362442'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/362442/cti'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.0085
epssPercentile: 0.56362
ingestedAt: '2026-07-24T07:21:20.989Z'
---

## Overview

A vulnerability was identified in Open5GS up to 2.7.7. This affects the function pcf_npcf_smpolicycontrol_handle_delete of the file src/pcf/sm-sm.c of the component delete Endpoint. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

## Affected

- `open5gs <= 2.7.7`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
