CVE-2026-107166
Open5GS GTP-U Receive Path gtp-path.c ogs_pfcp_xact_local_create allocation of resources
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
A weakness has been identified in Open5GS up to 2.7.7. This vulnerability affects the function ogs_pfcp_xact_local_create of the file src/upf/gtp-path.c of the component GTP-U Receive Path. This manipulation causes allocation of resources. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Patch name: 9ffc252482d9b03ac01abcedbe95497ff4f95dd0. It is recommended to apply a patch to fix this issue.
| CWE | CWE-770 CWE-400 |
| Vendor | n/a |
| Product | open5gs |
| Published | Oct 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for n/a open5gs
Be the first to know when new medium vulnerabilities affecting n/a open5gs are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
n/a / Open5GS
2.7.0 2.7.1 2.7.2 2.7.3 2.7.4 2.7.5 2.7.6 2.7.7
References
vuldb.com: https://vuldb.com/vuln/414968 vuldb.com: https://vuldb.com/vuln/414968/cti vuldb.com: https://vuldb.com/cve/CVE-2026-107166 vuldb.com: https://vuldb.com/submit/994175 github.com: https://github.com/open5gs/open5gs/issues/4792 github.com: https://github.com/open5gs/open5gs/pull/4806 github.com: https://github.com/open5gs/open5gs/commit/9ffc252482d9b03ac01abcedbe95497ff4f95dd0 github.com: https://github.com/open5gs/open5gs/
Credits
๐ ea1809 (VulDB User)