PatchSiren

Open5GS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Open5GS CVE published 2026-09-16

CVE-2026-92417

A vulnerability was found in Open5GS up to 2.8.0, specifically in the function ogs_pfcp_parse_volume_measurement within the library lib/pfcp/types.c of the PFCP Handler component. This vulnerability results in a null pointer dereference and can be exploited remotely. A patch, identified as 8f07b507b78ff94776f2cd49276eb116ed93d7f2, is available to remediate this issue.

LOW Open5GS CVE published 2026-08-30

CVE-2026-82589

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-30T23:17:07.800Z and has not been modified since then. A denial-of-service vulnerability exists in Open5GS up to 2.7.7 in the amf_namf_comm_handle_n1_n2_message_transfer function. The vulnerability can be triggered remotely by manipulating the N1N2MessageTransferReqData.n2InfoContainer.smInfo.n2Info [truncated]

MEDIUM Open5GS CVE published 2026-08-30

CVE-2026-82588

A vulnerability was identified in Open5GS up to 2.7.7. This issue affects some unknown processing of the file src/amf/namf-handler.c of the component Transfer Endpoint. Such manipulation leads to null pointer dereference. The attack can be launched remotely. Upgrading to version 2.8.0 is capable of addressing this issue. The name of the patch is abf8a836564b966b5141110fc25ed413c4f17522. Upgrading the affe [truncated]

LOW Open5GS CVE published 2026-08-30

CVE-2026-82587

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-30T19:17:30.050Z and has not been modified since then. Open5GS versions up to 2.7.7 are vulnerable to memory corruption via manipulation of the amf_namf_comm_decode_ue_mm_context_list function in src/amf/namf-handler.c. The attack can be initiated remotely and has been publicly disclosed. Upgrading [truncated]

HIGH Open5GS CVE published 2026-08-27

CVE-2026-37198

CVE-2026-37198 is a high-severity vulnerability in Open5GS v2.7.6 that allows attackers to cause a Denial of Service (DoS) via a crafted GTP packet. The vulnerability has a CVSS score of 7.5 and is considered high severity. Defenders should prioritize verifying exposure and assessing potential impact, as the vulnerability is in a widely used component and could lead to service disruption. Open5GS is an op [truncated]

HIGH Open5GS CVE published 2026-08-27

CVE-2026-30047

A reachable assertion vulnerability in Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via a crafted DELETE request to the /nsmf-pdusession/v1/sm-contexts component. This vulnerability's impact on service availability requires immediate attention from operators and security teams responsible for Open5GS deployments. Evidence is limited; verify Open5GS v2.7.6 /nsmf-pdusession/v1/sm-conte [truncated]

HIGH Open5GS CVE published 2026-08-27

CVE-2026-30046

A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request. This vulnerability has significant implications for administrators and users of Open5GS v2.7.6 installations, as it can lead to service disruptions. The vulnerability is classified as HIGH severity with a CVSS score of 7.5. Further inv [truncated]

HIGH open5gs CVE published 2026-08-27

CVE-2026-30045

An integer overflow in the /nnrf-disc/v1/nf-instances component of open5gs v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted HTTP/2 GET request. This vulnerability impacts service availability and requires prompt review and mitigation. Organizations should verify the /nnrf-disc/v1/nf-instances component and assess potential Denial of Service (DoS) risks. The CVE record was [truncated]

HIGH Open5GS CVE published 2026-08-18

CVE-2026-71676

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T20:17:24.917Z and has not been modified since then. This CVE-2026-71676 vulnerability, classified as a Buffer Overflow, affects Open5GS version 2.7.0. It allows a remote attacker to cause a denial of service via the NAS 5GS decoder chain. The vulnerability is triggered when the message type byte [truncated]

LOW Open5GS CVE published 2026-07-09

CVE-2026-15194

A security flaw has been discovered in Open5GS 2.7.7, affecting the amf_context_final function in src/amf/context.c of the AMF component, leading to a use-after-free vulnerability. Local access is required for the attack. The exploit has been publicly released and may be used for attacks. This vulnerability has significant implications for the security of Open5GS deployments, as it could potentially allow [truncated]

LOW Open5GS CVE published 2026-05-31

CVE-2026-10156

A low-severity resource consumption vulnerability exists in Open5GS up to version 2.7.7, specifically within the handle_amf_info function in /lib/sbi/nnrf-handler.c. The nf-instances endpoint is affected by manipulation of the nf_info_pool argument, which can be exploited remotely to cause resource exhaustion. The issue has been publicly disclosed with a published exploit, though the report is flagged as [truncated]

LOW Open5GS CVE published 2026-05-30

CVE-2026-10117

A remotely exploitable denial-of-service weakness exists in Open5GS through version 2.7.7, specifically within the ogs_pool_id_calloc function in /lib/sbi/nghttp2-server.c. The vulnerability has been publicly disclosed with exploit availability noted, though CVSS 4.0 scoring indicates LOW severity (2.1). The issue is classified under CWE-404 (Improper Resource Shutdown or Release). The CVE record was publ [truncated]

LOW Open5GS CVE published 2026-05-30

CVE-2026-10114

A low-severity out-of-bounds write vulnerability exists in Open5GS versions up to 2.7.7, specifically within the handle_scp_info function in lib/sbi/nnrf-handler.c. The flaw resides in the Shared NF-profile Parser component and can be triggered remotely. The issue has been publicly disclosed, with exploit availability noted. The CVSS 4.0 vector indicates network attack vector, low attack complexity, no pr [truncated]

LOW Open5gs CVE published 2026-05-17

CVE-2026-8746

CVE-2026-8746 describes a remote use-after-free affecting Open5GS up to version 2.7.7 in the NRF component’s discover_handler function. The record rates the issue as low severity, but it is network-exposed and potentially relevant for any deployment that exposes Open5GS SBI/NRF services. The source description also says a public exploit has been released and that the project was informed early via an issu [truncated]

LOW Open5gs CVE published 2026-05-17

CVE-2026-8745

CVE-2026-8745 describes a remote denial-of-service issue in Open5GS AUSF, affecting versions up to 2.7.7. The source corpus ties the flaw to ogs_timer_add in src/ausf/nausf-handler.c and classifies it as a low-severity availability impact issue. The record also says the project was notified early via an issue report and had not responded at the time of publication.

LOW Open5gs CVE published 2026-05-17

CVE-2026-8744

CVE-2026-8744 affects Open5GS NRF logic in /lib/sbi/context.c and can be triggered remotely to cause denial of service. The CVE description ties the issue to ogs_sbi_subscription_data_add and ogs_sbi_nf_service_add, and states that a public exploit disclosure exists. Even though the assigned CVSS score is low, exposed Open5GS NRF deployments should treat this as a real operational risk because availabilit [truncated]

LOW Open5gs CVE published 2026-05-17

CVE-2026-8743

CVE-2026-8743 is a remote improper-authorization issue in Open5GS AMF/MME context handling, specifically in ran_ue_find_by_amf_ue_ngap_id within src/amf/context.c. The supplied description says versions up to 2.7.6 are affected and that a public exploit exists, so this should be treated as a real exposure even though the published CVSS score is low (2.1).

LOW Open5gs CVE published 2026-05-17

CVE-2026-8731

CVE-2026-8731 describes a denial-of-service flaw in Open5GS’s NRF component, specifically in ogs_sbi_client_add within lib/sbi/client.c. The issue is reported as remotely reachable, publicly disclosed, and tied to manipulation of client_pool, with the supplied NVD record assigning CWE-404 and a low CVSS 4.0 score of 2.1.

LOW Open5gs CVE published 2026-05-17

CVE-2026-8730

CVE-2026-8730 is a low-severity denial-of-service issue in Open5GS’s NRF component. According to the published record, manipulating the nfInstanceId argument in ogs_sbi_nf_instance_set_id can disrupt service remotely, and an exploit has already been published. The issue is reported to affect Open5GS up to version 2.7.6.

LOW Open5gs CVE published 2026-05-17

CVE-2026-8729

CVE-2026-8729 is a remote denial-of-service issue reported in Open5GS NRF code, affecting versions up to 2.7.7. The source description says manipulation of the service-names/snssais arguments in /lib/sbi/message.c can disrupt service, and that a public exploit exists. Because the affected component is part of the NRF path, operators should treat exposed or production Open5GS deployments as potentially imp [truncated]

LOW Open5gs CVE published 2026-05-17

CVE-2026-8728

CVE-2026-8728 describes a denial-of-service condition in Open5GS’s NRF component, specifically in ogs_sbi_discovery_option_parse_plmn_list within lib/sbi/conv.c. According to the CVE record, malformed manipulation of the target-plmn-list argument can be used remotely to disrupt service. The record also says the issue was disclosed publicly and that the project had been informed early through an issue repo [truncated]

LOW Open5gs CVE published 2026-05-11

CVE-2026-8268

CVE-2026-8268 is a denial of service vulnerability in the OpenAPI_list_create function of the SMF component in Open5GS up to 2.7.7. The vulnerability can be exploited remotely. Users of Open5GS should be aware of this issue and take necessary precautions until a patch is available. This includes reviewing system configurations, monitoring for potential exploitation attempts, and planning for an upgrade to [truncated]

LOW Open5GS CVE published 2026-05-11

CVE-2026-8267

A denial of service vulnerability was found in Open5GS up to 2.7.7 in the SMF component. The vulnerability affects the function smf_nsmf_handle_created_data_in_vsmf. The attack may be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet. Users should review their installations and consider compensating controls. This vulnerability has been pub [truncated]

LOW Open5GS CVE published 2026-05-11

CVE-2026-8266

A vulnerability was detected in Open5GS up to 2.7.7, affecting the SMF component's gsm_build_pdu_session_establishment_accept function in /src/smf/gsm-build.c. The manipulation results in denial of service. The attack can be launched remotely. Users should review official advisories and CVE records for affected scope, severity, and vendor guidance. This issue has a low CVSS score of 2.1, indicating a low [truncated]

LOW Open5GS CVE published 2026-05-11

CVE-2026-8252

A vulnerability was determined in Open5GS up to 2.7.7, affecting the function smf_nsmf_handle_create_data_in_hsmf of the component SMF. Executing a manipulation can lead to null pointer dereference. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. This vulne [truncated]

LOW Open5GS CVE published 2026-05-10

CVE-2026-8251

A vulnerability was found in Open5GS up to 2.7.7. This impacts the function update_authorized_pcc_rule_and_qos of the file /src/smf/npcf-handler.c of the component SMF. Performing a manipulation results in denial of service. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has no [truncated]

LOW Open5GS CVE published 2026-05-10

CVE-2026-8250

A vulnerability was found in Open5GS up to 2.7.7 in the SMF component. The smf_n4_build_qos_flow_to_modify_list function in /src/smf/n4-build.c can be manipulated remotely to cause a denial of service. The project was informed but has not responded yet. This issue is related to the denial of service vulnerability in the SMF component of Open5GS. The vulnerability affects the SMF component of Open5GS, whic [truncated]

LOW Open5GS CVE published 2026-05-10

CVE-2026-8249

CVE-2026-8249 is a denial of service vulnerability in the SMF component of Open5GS, specifically in the function update_authorized_pcc_rule_and_qos of the file /src/smf/npcf-handler.c. The vulnerability has a CVSS score of 2.1 and is considered low severity. Remote exploitation is possible, and an exploit has been published. Users of Open5GS up to version 2.7.7 should be aware of this denial of service vu [truncated]

LOW Open5gs CVE published 2026-05-08

CVE-2026-8123

CVE-2026-8123 is a low-severity but operationally relevant denial-of-service issue in Open5GS up to 2.7.7. According to the NVD record, the affected path is ogs_sbi_discovery_option_add_snssais in /lib/sbi/message.c within the NSSF component, and the issue can be triggered remotely. The record also notes that exploit details have been publicly disclosed and that the project was notified early via an issue report.

LOW Open5gs CVE published 2026-05-08

CVE-2026-8122

CVE-2026-8122 is a denial-of-service issue reported in Open5GS NSSF, specifically in ogs_sbi_discovery_option_add_service_names within /lib/sbi/message.c. The supplied record says affected versions extend through 2.7.7, the attack can be performed remotely, and a public exploit has been referenced. NVD has analyzed the issue and assigns a low availability impact in its CVSS v4.0 vector, but the combinatio [truncated]