๐Ÿ” CVE Alert

CVE-2026-107166

MEDIUM 5.3

Open5GS GTP-U Receive Path gtp-path.c ogs_pfcp_xact_local_create allocation of resources

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

A weakness has been identified in Open5GS up to 2.7.7. This vulnerability affects the function ogs_pfcp_xact_local_create of the file src/upf/gtp-path.c of the component GTP-U Receive Path. This manipulation causes allocation of resources. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Patch name: 9ffc252482d9b03ac01abcedbe95497ff4f95dd0. It is recommended to apply a patch to fix this issue.

CWE CWE-770 CWE-400
Vendor n/a
Product open5gs
Published Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for n/a open5gs

Be the first to know when new medium vulnerabilities affecting n/a open5gs are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

n/a / Open5GS
2.7.0 2.7.1 2.7.2 2.7.3 2.7.4 2.7.5 2.7.6 2.7.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/414968 vuldb.com: https://vuldb.com/vuln/414968/cti vuldb.com: https://vuldb.com/cve/CVE-2026-107166 vuldb.com: https://vuldb.com/submit/994175 github.com: https://github.com/open5gs/open5gs/issues/4792 github.com: https://github.com/open5gs/open5gs/pull/4806 github.com: https://github.com/open5gs/open5gs/commit/9ffc252482d9b03ac01abcedbe95497ff4f95dd0 github.com: https://github.com/open5gs/open5gs/

Credits

๐Ÿ” ea1809 (VulDB User)