ZeroHour

CVE-2026-75438

niche

Buffer Overflow DoS in Open5GS 5G Core SBI Time Parser

CVSS 3.1
7.5 high
EPSS
<1%p39
Published
()
Modified
AI analysis

CVE-2026-75438 is a buffer overflow (CWE-120) in the ogs_sbi_time_parse() function of Open5GS v2.7.7, the open-source 4G/5G core network implementation. A remote attacker can trigger the flaw by sending malformed time-formatted input to an Open5GS network function's service-based interface (SBI), causing the parser to write past the bounds of a buffer. The impact is a crash of the affected network function, i.e. a denial of service; the CVSS vector confirms no confidentiality or integrity impact, only high availability impact, and no authentication or user interaction is required. Any operator or organization running Open5GS v2.7.7 is affected, particularly deployments where SBI-facing services are reachable by untrusted clients. Exploitation status: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at only about 0.5%.

What to do: Operators running Open5GS v2.7.7 should check the upstream Open5GS project (GitHub releases/security advisories) for a patched version and upgrade as soon as a fix is published, since no fixed version is named in the available data. As an interim mitigation, restrict network access to SBI-facing network functions (the HTTP/2 service interfaces) so only trusted internal components can reach them, and monitor for unexpected NF process crashes or restarts.

Affected
Open5GS project Open5GS (open-source 5G Core / EPC)v2.7.7 (the only version named in the advisory; other affected ranges not stated in the available data)
Estimated exposure
nicheon the order of a few thousand deployments worldwide (labs, private 5G networks, small operators), with an unknown but smaller subset of SBI interfaces exposed… — Open5GS is a specialized open-source telecom core with no public install-count telemetry, so the estimate is based on its typical adoption pattern (research testbeds, private-network trials, and small/regional operators) and the fact that…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_parse() function

Weakness
CWE-120
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.