Open5GS: Four Medium-Severity Flaws in SMF and AMF Disclosed Together
Four medium-severity vulnerabilities were disclosed in Open5GS on August 30, 2026, affecting core network functions and patched in version 2.8.0.

Key findings
- Four medium-severity vulnerabilities disclosed together for Open5GS on August 30, 2026.
- Vulnerabilities affect SMF and AMF components in Open5GS versions up to 2.7.7.
- Flaws include reachable assertion, null pointer dereference, and memory corruption.
- All issues are addressed in Open5GS version 2.8.0.
On August 30, 2026, a batch of four medium-severity vulnerabilities was disclosed for Open5GS, a 5G core network software suite. These vulnerabilities, all discovered and reported on the same day, affect versions of Open5GS up to 2.7.7 and were fixed in version 2.8.0. The disclosures highlight potential weaknesses in critical components of the 5G core, including the Session Management Function (SMF) and the Access and Mobility Management Function (AMF).
Three of the four vulnerabilities (CVE-2026-82589, CVE-2026-82588, and CVE-2026-82587) stem from issues within the AMF component, specifically related to the handling of N1-N2 messages and UE (User Equipment) context information. CVE-2026-82589 involves a manipulation of the N2InfoContainer within the N1-N2 Message Transfer, while CVE-2026-82588 is a null pointer dereference vulnerability in the Transfer Endpoint processing. CVE-2026-82587 details memory corruption caused by manipulating the allowed NSSAI within the UE MM context list. These flaws could potentially be exploited remotely by an attacker.
The fourth vulnerability, CVE-2026-82590, is located in the SMF component and affects the smf_nudm_sdm_handle_get function. A manipulation of the preemptCap argument can lead to a reachable assertion, which could also be exploited remotely.
All identified vulnerabilities affect Open5GS versions prior to 2.7.7. The vendor has addressed these issues by releasing version 2.8.0. Users of Open5GS are strongly advised to upgrade to the patched version to mitigate the risks associated with these vulnerabilities. The coordinated disclosure of these four medium-severity flaws on a single day underscores the importance of timely patching and security updates for core network infrastructure.