PatchSiren cyber security CVE debrief
CVE-2026-107166 Open5GS CVE debrief
A weakness in Open5GS up to 2.7.7 affects the GTP-U Receive Path, specifically the ogs_pfcp_xact_local_create function in gtp-path.c, leading to resource allocation. The attack can be carried out remotely, and a patch is available. This vulnerability impacts Open5GS installations, and defenders should assess exposure and prioritize patching to prevent potential resource allocation weaknesses. The affected component is part of the GTP-U Receive Path, which is a critical area for telecommunications infrastructure. The vulnerability class is related to resource allocation, which can lead to denial-of-service or other security issues if exploited.
- Vendor
- Open5GS
- Product
- Open5GS
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Open5GS installations should assess exposure and prioritize patching to prevent potential resource allocation weaknesses. This includes reviewing and updating Open5GS installations to ensure version 2.7.7 or earlier is patched, monitoring for potential remote attacks on Open5GS GTP-U Receive Path, and verifying patch application to prevent resource allocation weaknesses. Security teams should also track exceptions, retest remedi
Why it matters
Defenders should prioritize patching Open5GS installations to prevent potential resource allocation weaknesses that could be exploited remotely.
- Verify patch application to prevent resource allocation weaknesses
- Assess Open5GS GTP-U Receive Path exposure to remote attacks
- Monitor for potential resource allocation issues in Open5GS installations
Technical summary
The ogs_pfcp_xact_local_create function in gtp-path.c of Open5GS up to 2.7.7 is vulnerable to resource allocation weaknesses, allowing remote attacks. This function is part of the GTP-U Receive Path and is critical for telecommunications infrastructure. The vulnerability is caused by improper resource allocation, which can lead to denial-of-service or other security issues if exploited. Defenders should prioritize patching Open5GS installations to prevent potential resource allocation weaknesses. The vulnerability has been made public, and a patch is available.
Defensive priority
Defenders should prioritize patching Open5GS installations to prevent potential resource allocation weaknesses.
Recommended defensive actions
- Apply the patch (9ffc252482d9b03ac01abcedbe95497ff4f95dd0) to fix the issue
- Review and update Open5GS installations to ensure version 2.7.7 or earlier is patched
- Monitor for potential remote attacks on Open5GS GTP-U Receive Path
- Verify patch application to prevent resource allocation weaknesses
- Assess Open5GS GTP-U Receive Path exposure to remote attacks
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE Program record and NVD detail page provide official information about the vulnerability. Supplemental sources, including VulDB entries and GitHub issue tracking, offer additional context. The vulnerability has been made public, and a patch is available at 9ffc252482d9b03ac01abcedbe95497ff4f95dd0. Defenders should verify patch application and assess Open5GS GTP-U Receive Path exposure to remote attacks. The CVE record was published on 2026-10-07T16:00:09.165Z and has not been modified since then. The information provided is is
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107166 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107166
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107166 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107166
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Open5GS GTP-U Receive Path gtp-path.c ogs_pfcp_xact_local_create allocation of resources
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107166.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/414968
Supplemental source - vdb-entry, technical-description
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/414968/cti
Supplemental source - signature, permissions-required
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-107166
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/994175
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/open5gs/open5gs/issues/4792
Supplemental source - exploit, issue-tracking
-
Source reference
Unverified legacy reference
URL: https://github.com/open5gs/open5gs/pull/4806
Supplemental source - issue-tracking, patch
-
Source reference
Unverified legacy reference
URL: https://github.com/open5gs/open5gs/commit/9ffc252482d9b03ac01abcedbe95497ff4f95dd0
Supplemental source - patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.