A vulnerability was found in Open5GS up to 2.7.7. It has been declared as problematic. This vulnerability affects the function bsf_sess_add_by_ip_address of the file /nbsf-management/v1/pcfBindings of the component BSF. Executing a manipulation of the argument ipv4Addr can lead to denial of service.

This vulnerability is tracked as CVE-2026-7536. The attack can be launched remotely. Moreover, an exploit is present.

The project was informed of the problem early through an issue report but has not responded yet.