---
id: CVE-2026-8252
title: A vulnerability was determined in Open5GS up to 2.7.7
summary: >-
  A vulnerability was determined in Open5GS up to 2.7.7. Affected is the
  function smf_nsmf_handle_create_data_in_hsmf of the component SMF. Executing a
  manipulation can lead to null pointer dereference. The attack may be performed
  from rem…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-404
  - CWE-476
vendor: open5gs
product: open5gs
affected:
  - open5gs <= 2.7.7
published: '2026-05-11'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-8252'
references:
  - url: 'https://github.com/open5gs/open5gs/'
    label: cna@vuldb.com
  - url: 'https://github.com/open5gs/open5gs/issues/4446'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/808482'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/362549'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/362549/cti'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00378
epssPercentile: 0.31661
ingestedAt: '2026-07-24T07:21:21.634Z'
---

## Overview

A vulnerability was determined in Open5GS up to 2.7.7. Affected is the function smf_nsmf_handle_create_data_in_hsmf of the component SMF. Executing a manipulation can lead to null pointer dereference. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

## Affected

- `open5gs <= 2.7.7`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
