Vulnerabilities
154 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-8744 | A vulnerability was determined in Open5GS up to 2.7.7. A vulnerability was determined in Open5GS up to 2.7.7. Affected is the function ogs_sbi_subscription_data_add/ogs_sbi_nf_service_add in the library /lib/sbi/context.c of the component NRF. Executing a manipulation can lead to denial of service. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. This patch is called 819db11a08b9736a3576c4f99ceb28f7eb99523a. A patch should be applied to remediate this issue. NVD description · AI analysis pending | 2.1 | <1% | PoC ×2 |
| — | |
| CVE-2026-8269 | A vulnerability was found in Open5GS up to 2.7.7. A vulnerability was found in Open5GS up to 2.7.7. Impacted is the function smf_nsmf_handle_create_sm_context of the component SMF. Performing a manipulation results in denial of service. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. NVD description · AI analysis pending | 2.1 | <1% | PoC |
| — | |
| CVE-2026-8224 | A vulnerability was determined in Open5GS up to 2.7.7. A vulnerability was determined in Open5GS up to 2.7.7. Affected by this issue is the function pcf_sess_set_ipv6prefix of the file /src/pcf/context.c of the component PCF. Executing a manipulation of the argument SmPolicyContextData.ipv6AddressPrefix can lead to denial of service. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.5 group max | <1% | PoC |
| — | |
| CVE-2026-8187 +1 in the same advisory: …8186 | A flaw has been found in Open5GS up to 2.7.7. A flaw has been found in Open5GS up to 2.7.7. This impacts the function _gtpv1_u_recv_cb of the file src/upf/gtp-path.c of the component UPF. Executing a manipulation can lead to resource consumption. The attack may be performed from remote. The project was informed of the problem early through an issue report but has not responded yet. NVD description · AI analysis pending | 6.9 | <1% | PoC |
| — | |
| CVE-2026-8121 | A vulnerability has been found in Open5GS up to 2.7.7. A vulnerability has been found in Open5GS up to 2.7.7. The impacted element is the function ogs_sbi_parse_plmn_list in the library /lib/sbi/conv.c of the component NSSF. The manipulation leads to denial of service. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet. NVD description · AI analysis pending | 2.1 group max | <1% | PoC ×2 |
| — | |
| CVE-2026-7585 | A vulnerability was determined in Open5GS up to 2.7.7. A vulnerability was determined in Open5GS up to 2.7.7. The impacted element is the function amf_nudm_sdm_handle_provisioned of the file /src/amf/nudm-handler.c of the component AMF. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. NVD description · AI analysis pending | 2.1 | <1% |
| — | ||
| CVE-2026-4988 | A security flaw has been discovered in Open5GS 2.7.6. A security flaw has been discovered in Open5GS 2.7.6. This issue affects the function smf_gx_cca_cb/smf_gy_cca_cb/smf_s6b of the component CCA Message Handler. The manipulation results in denial of service. The attack may be launched remotely. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit has been released to the public and may be used for attacks. NVD description · AI analysis pending | 2.9 | <1% | PoC ×2 |
| — | |
| CVE-2026-4240 | A vulnerability was determined in Open5GS up to 2.7.6. A vulnerability was determined in Open5GS up to 2.7.6. The affected element is the function smf_gx_cca_cb/smf_gy_cca_cb/smf_s6b_aaa_cb/smf_s6b_sta_cb of the component CCA Handler. This manipulation causes denial of service. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.7.7 is sufficient to fix this issue. Patch name: 80eb484a6ab32968e755e628b70d1a9c64f012ec. Upgrading the affected component is recommended. NVD description · AI analysis pending | 5.5 | <1% | PoC ×2 |
| — | |
| CVE-2026-2524 | A flaw has been found in Open5GS 2.7.6. A flaw has been found in Open5GS 2.7.6. The impacted element is the function mme_s11_handle_create_session_response of the component MME. This manipulation causes denial of service. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. NVD description · AI analysis pending | 5.5 | <1% | PoC ×2 |
| — | |
| CVE-2026-2521 +1 in the same advisory: …2517 | A weakness has been identified in Open5GS up to 2.7.6. A weakness has been identified in Open5GS up to 2.7.6. This issue affects the function sgwc_s5c_handle_create_session_response of the component SGW-C. Executing a manipulation can lead to memory corruption. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. NVD description · AI analysis pending | 5.5 | <1% | PoC ×2 |
| — | |
| CVE-2026-2062 | A vulnerability was identified in Open5GS up to 2.7.6. A vulnerability was identified in Open5GS up to 2.7.6. This affects the function sgwc_s5c_handle_modify_bearer_response/sgwc_sxa_handle_session_modification_response of the component PGW S5U Address Handler. The manipulation leads to null pointer dereference. The attack can be initiated remotely. The exploit is publicly available and might be used. The identifier of the patch is f1bbd7b57f831e2a070780a7d8d5d4c73babdb59. Applying a patch is the recommended action to fix this issue. NVD description · AI analysis pending | 5.5 | <1% | PoC ×2 |
| — | |
| CVE-2025-15555 | A security flaw has been discovered in Open5GS up to 2.7.6. A security flaw has been discovered in Open5GS up to 2.7.6. Affected by this vulnerability is the function hss_ogs_diam_cx_mar_cb of the file src/hss/hss-cx-path.c of the component VoLTE Cx-Test. The manipulation of the argument OGS_KEY_LEN results in stack-based buffer overflow. The attack may be launched remotely. The patch is identified as 54dda041211098730221d0ae20a2f9f9173e7a21. A patch should be applied to remediate this issue. NVD description · AI analysis pending | 6.9 | <1% | PoC ×2 |
| — | |
| CVE-2026-1738 | A flaw has been found in Open5GS up to 2.7.6. A flaw has been found in Open5GS up to 2.7.6. The impacted element is the function sgwc_tunnel_add of the file /src/sgwc/context.c of the component SGWC. Executing a manipulation of the argument pdr can lead to reachable assertion. The attack can be executed remotely. The exploit has been published and may be used. It is advisable to implement a patch to correct this issue. The issue report is flagged as already-fixed. NVD description · AI analysis pending | 5.5 | <1% | PoC ×2 |
| — |