CVE-2026-7583 — Open5GS Denial of Service
CVE-2026-7583 — A flaw has been found in Open5GS up to 2.7.7. This issue affects the function bsf_sess_find_by_ipv6prefix of the file /src/bsf/context.c of the component BSF. This manipulation of the argument ipv6Prefix causes denial of service. It is possible to initiate the attack remotely. The ex
What This Means For You
- If your environment is affected by CWE-404, review your exposure and prioritize patching based on your environment. Monitor vendor advisories for CVE-2026-7583 updates and patches.
Related ATT&CK Techniques
🛡️ Detection Rules
2 rules · 6 SIEM formats2 detection rules auto-generated for this incident, mapped to MITRE ATT&CK. Sigma YAML is free — export to any SIEM format via the Intel Bot.
CVE-2026-7583 - Open5GS BSF Denial of Service via IPv6 Prefix Manipulation
title: CVE-2026-7583 - Open5GS BSF Denial of Service via IPv6 Prefix Manipulation
id: scw-2026-05-01-ai-1
status: experimental
level: high
description: |
Detects attempts to exploit CVE-2026-7583 in Open5GS by targeting the bsf_sess_find_by_ipv6prefix function. The rule looks for HTTP POST requests to a URI containing '/bsf/context.c' and a query parameter 'ipv6Prefix', indicating a potential manipulation of the IPv6 prefix argument to cause a denial of service.
author: SCW Feed Engine (AI-generated)
date: 2026-05-01
references:
- https://shimiscyberworld.com/posts/nvd-CVE-2026-7583/
tags:
- attack.initial_access
- attack.t1190
logsource:
category: webserver
detection:
selection:
cs-uri|contains:
- '/bsf/context.c'
cs-uri-query|contains:
- 'ipv6Prefix='
cs-method:
- 'POST'
condition: selection
falsepositives:
- Legitimate administrative activity
Source: Shimi's Cyber World · License & reuse
Indicators of Compromise
| ID | Type | Indicator |
|---|---|---|
| CVE-2026-7583 | vulnerability | CVE-2026-7583 |
| CWE-404 | weakness | CWE-404 |
Source & Attribution
| Source Platform | NVD |
| Channel | National Vulnerability Database |
| Published | May 01, 2026 at 18:16 UTC |
This content was curated and summarized by Shimi's Cyber World for informational purposes. It is not copied or republished in full. All intellectual property rights remain with the original author and source.
Believe this infringes your rights? Submit a takedown request.