ZeroHour

CVE-2026-30045

niche

Integer Overflow DoS in Open5GS NRF NF-Discovery Service

CVSS 3.1
7.5 high
EPSS
<1%p33
Published
()
Modified
AI analysis

CVE-2026-30045 is an integer overflow (CWE-190) in the /nnrf-disc/v1/nf-instances component of Open5GS v2.7.6, the open-source 4G/5G core's Network Repository Function (NRF) that handles network-function discovery. An attacker can trigger it by sending a single crafted HTTP/2 GET request to the NF-discovery endpoint on the service-based-interface (SBI) listener. The successful request crashes the affected component, causing a denial of service that can disrupt network-function discovery and degrade the core network; there is no confidentiality or integrity impact per the CVSS vector. Anyone running Open5GS v2.7.6 with the NRF discovery service reachable over HTTP/2 is affected — typically private 5G network operators, labs, and research deployments — and no authentication is required. As of this analysis there is no known public proof-of-concept, the flaw is not in the CISA KEV catalog, and its EPSS score (0.4%, ~33rd percentile) suggests a low near-term probability of exploitation.

What to do: Upgrade Open5GS to the latest release that fixes this issue (the advisory names v2.7.6 as affected; check the Open5GS changelog/GitHub advisories for the fixed version). In the interim, restrict access to the NRF/SBI HTTP/2 listener (the service-based interface, typically not meant for untrusted networks) using firewall or ACL rules so only trusted network functions can reach /nnrf-disc/v1/nf-instances. Monitor 5G core logs for unexpected NRF process crashes or malformed HTTP/2 GET requests against the discovery endpoint.

Affected
Open5GS project (open source) Open5GSv2.7.6 (version named in the advisory; other versions not confirmed in available data)
Estimated exposure
nichelikely low thousands of deployments (private 5G cores, labs, research testbeds); no public scan data available — Open5GS is an open-source 4G/5G core most commonly deployed in private-network, lab, and research settings rather than mass-market services, and the affected NRF SBI endpoint is normally reachable only from the internal core network, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An integer overflow in the /nnrf-disc/v1/nf-instances component of open5gs v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted HTTP/2 GET request.

Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.