---
id: CVE-2026-90707
title: A security flaw has been discovered in Open5GS up to 2.7.x
summary: >-
  A security flaw has been discovered in Open5GS up to 2.7.x. Affected is the
  function amf_nnrf_try_old_amf_discovery_fallback of the file
  src/amf/nnrf-handler.c of the component Old AMF Discovery Fallback. The
  manipulation of the argument…
severity: high
cvss: 8.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L'
cwe:
  - CWE-119
  - CWE-416
product: Open5GS
affected:
  - Open5GS 2.0
  - Open5GS 2.1
  - Open5GS 2.2
  - Open5GS 2.3
  - Open5GS 2.4
  - Open5GS 2.5
  - Open5GS 2.6
  - Open5GS 2.7
published: '2026-09-14'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T14:17:32.230'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90707'
references:
  - url: 'https://github.com/open5gs/open5gs/'
    label: cna@vuldb.com
  - url: >-
      https://github.com/open5gs/open5gs/commit/ddd683a35f8aaac2b7b9884a24cd53bddfc65238
    label: cna@vuldb.com
  - url: 'https://github.com/open5gs/open5gs/pull/4698'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90707'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/918267'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403249'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403249/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-15T13:33:46.758197Z'
epss: 0.00527
epssPercentile: 0.42148
ingestedAt: '2026-09-14T15:23:07.462Z'
---

## Overview

A security flaw has been discovered in Open5GS up to 2.7.x. Affected is the function amf_nnrf_try_old_amf_discovery_fallback of the file src/amf/nnrf-handler.c of the component Old AMF Discovery Fallback. The manipulation of the argument discovery_option results in use after free. The attack may be performed from remote. The patch is identified as ddd683a35f8aaac2b7b9884a24cd53bddfc65238. Applying a patch is advised to resolve this issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
