CVE-2026-37198
moderateInteger Overflow DoS in Open5GS SMF via Crafted GTP Packets
CVE-2026-37198 is an integer overflow (CWE-190) in the Session Management Function (SMF) component of Open5GS, the open-source 4G/5G core network, reported in version v2.7.6. It is triggered by sending a crafted GTP packet to the affected GTP handling path over the network, requiring no authentication and no user interaction. A successful attack causes a high-availability impact only: the SMF can crash or become unavailable, disrupting subscriber session management, with no confidentiality or integrity impact per the CVSS vector. Affected parties are operators and integrators running Open5GS, particularly deployments whose GTP interfaces are reachable beyond fully trusted radio/transport networks, such as lab, private-network, and small-operator setups. No exploitation in the wild, public proof-of-concept, or KEV listing is known; EPSS is 0.4% (38th percentile), indicating low near-term exploitation probability.
What to do: Upgrade Open5GS to a patched release as soon as one is published (check the project's GitHub releases/security advisories for a fix beyond v2.7.6). Until patched, restrict GTP traffic (typically UDP port 2152) with firewall/ACL rules to known eNodeB/gNB and SGW/UPF peers only, and monitor the SMF for crashes or restarts. Since the flaw is unauthenticated and availability-only, prioritize hosts whose GTP interface is reachable from untrusted or shared networks.
| Open5GS (SMF component) | v2.7.6 (version cited in the advisory; check project advisories for the full affected range) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An integer overflow in the SMF component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted GTP packet.
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.