


Perceptive Security
SOC/SIEM Consultancy

A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via s…
Published:
27 August 2026 at 00:00:00
Alert date:
27 August 2026 at 23:07:34
Source:
nvd.nist.gov
Network Infrastructure, Critical Infrastructure, Emerging Technologies
CVE-2026-30047 is a reachable assertion vulnerability found in the /nsmf-pdusession/v1/sm-contexts component of Open5GS version 2.7.6. Attackers can exploit this flaw by sending a specially crafted DELETE request, triggering an assertion failure that results in a Denial of Service (DoS) condition. Open5GS is an open-source implementation of 5G core network functions, making this vulnerability relevant to telecom and network infrastructure environments. The vulnerability has been documented in the NVD and tracked via a corresponding GitHub issue. No authentication context is specified, suggesting the endpoint may be reachable without elevated privileges. The DoS impact could disrupt session management functions critical to 5G network operation. The severity has been assessed as High.
Technical details
Mitigation steps:
Affected products:
Open5GS v2.7.6
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
