CVE-2026-8746 is a use-after-free vulnerability in Open5GS, an open-source implementation of 5G and 4G mobile core network functions used by researchers, labs, and some production private-network deployments.
What the vulnerability does
The flaw sits in the discover_handler function inside lib/sbi/nghttp2-server.c, part of Open5GS’s NRF (Network Repository Function) component — the core-network element responsible for service discovery and registration among other 5G network functions. Per the ingested vulnerability record, manipulation of this handler triggers a use-after-free condition, and the attack can be launched remotely. Affected versions run up through 2.7.7.
Use-after-free bugs in a network-facing service-discovery handler are a meaningful class of risk: depending on how the freed memory is reused, exploitation can range from a crash (denial of service against a core network function) up to memory corruption that could be leveraged for further compromise, though our ingested data doesn’t confirm which outcome is achievable here.
Disclosure status
The vulnerability record notes the exploit has already been released publicly. It also states the Open5GS project “was informed of the problem early through an issue report but has not responded yet” — meaning, as of this writing, there is no confirmed vendor fix or patched version to point to. This is a disclosure gap, not a resolved advisory.
What we don’t yet have
We don’t have a CVSS vector breakdown, a confirmed patched version, or an official Open5GS security advisory acknowledging the report — only the underlying GitHub issue and the vulnerability’s own technical description. Treat the “no vendor response yet” status as current as of this writing; operators should track the upstream Open5GS issue tracker directly for a fix rather than relying on this article for patch-version guidance.
Confidence
Confidence is medium: the technical root cause (a specific function and file) is well-specified, but the lack of an acknowledged vendor advisory or confirmed fix version means this hasn’t gone through the validation a formal disclosure process would provide.
Why this matters
Open5GS underpins real 5G/4G core-network testbeds and some production private networks. A publicly available exploit against an unpatched, unacknowledged use-after-free in the NRF component is a genuine operational risk for anyone running an affected deployment exposed to untrusted network paths — operators should isolate NRF interfaces from untrusted networks as a mitigating control until an official fix lands, and monitor the upstream project directly.
Frequently Asked Questions
What is CVE-2026-8746?
A use-after-free vulnerability in the NRF component of Open5GS (versions up to 2.7.7), triggerable remotely via the discover_handler function, with a public exploit and no confirmed vendor fix as of this writing.
Is there a patch for CVE-2026-8746? Not as of this writing — the Open5GS project has been notified but has not yet responded, per the available disclosure record.
Is CVE-2026-8746 being actively exploited? No evidence of active in-the-wild exploitation has been reported; it is not listed in CISA’s KEV catalog, though a proof-of-concept exploit is reportedly public.
Data sourced from the Open5GS project’s public issue tracker, aggregated September 2026. See more vulnerability intelligence.