VYPR

Open5gs

by Open5gs

Source repositories

CVEs (205)

  • CVE-2026-90707HigSep 14, 2026
    risk 0.47cvss 8.3epss 0.00

    A security flaw has been discovered in Open5GS up to 2.7.x. Affected is the function amf_nnrf_try_old_amf_discovery_fallback of the file src/amf/nnrf-handler.c of the component Old AMF Discovery Fallback. The manipulation of the argument discovery_option results in use after…

  • CVE-2023-37013HigJan 22, 2025
    risk 0.47cvss 7.3epss 0.01

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a sufficiently large ASN.1 packet over the S1AP interface. An attacker may repeatedly send such an oversized packet to cause the `ogs_sctp_recvmsg` routine to reach an unexpected network state…

  • CVE-2025-29646HigJun 18, 2025
    risk 0.46cvss 7.1epss 0.00

    An issue in upf in open5gs 2.7.2 and earlier allows a remote attacker to cause a Denial of Service via a crafted PFCP SessionEstablishmentRequest packet with restoration indication = true and (teid = 0 or teid >= ogs_pfcp_pdr_teid_pool.size).

  • CVE-2026-75438HigSep 4, 2026
    risk 0.42cvss 7.5epss 0.00

    Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_parse() function

  • CVE-2026-30047HigAug 27, 2026
    risk 0.42cvss 7.5epss 0.00

    A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.

  • CVE-2026-30046HigAug 27, 2026
    risk 0.42cvss 7.5epss 0.00

    A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.

  • CVE-2026-30045HigAug 27, 2026
    risk 0.42cvss 7.5epss 0.00

    An integer overflow in the /nnrf-disc/v1/nf-instances component of open5gs v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted HTTP/2 GET request.

  • CVE-2025-56568HigApr 30, 2026
    risk 0.42cvss 7.5epss 0.00

    Assertion failure vulnerability in the PCO (Protocol Configuration Options) parser in the SMF (Session Management Function) component of Open5GS before v2.7.5 allows remote attackers to cause denial of service via specially crafted NGAP messages containing malformed length…

  • CVE-2026-0622MedJan 20, 2026
    risk 0.42cvss 6.5epss 0.00

    Open 5GS WebUI uses a hard-coded JWT signing key (change-me) whenever the environment variable JWT_SECRET_KEY is unset

  • CVE-2023-4885MedOct 3, 2023
    risk 0.42cvss 6.5epss 0.00

    Man in the Middle vulnerability, which could allow an attacker to intercept VNF (Virtual Network Function) communications resulting in the exposure of sensitive information.

  • CVE-2023-4884MedOct 3, 2023
    risk 0.42cvss 6.5epss 0.01

    An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to the lack of Authentication.

  • CVE-2026-78157HigAug 24, 2026
    risk 0.41cvss 7.4epss 0.00

    A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the file src/pcrf/pcrf-rx-path.c of the component Rx AA-Request Handler. Performing a manipulation results in out-of-bounds read. It is possible to initiate the attack remotely. The patch…

  • CVE-2026-78156HigAug 24, 2026
    risk 0.41cvss 7.4epss 0.00

    A security vulnerability has been detected in Open5GS 2.8.0. Affected by this issue is the function hss_ogs_diam_s6a_air_cb of the file src/hss/hss-s6a-path.c of the component S6a Authentication-Information-Request Handler. Such manipulation of the argument Visited-PLMN-Id leads…

  • CVE-2023-37011MedJan 22, 2025
    risk 0.41cvss 6.3epss 0.00

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Required` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial…

  • CVE-2023-37010MedJan 22, 2025
    risk 0.41cvss 6.3epss 0.00

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `eNB Status Transfer` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in…

  • CVE-2023-37009MedJan 22, 2025
    risk 0.41cvss 6.3epss 0.00

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Notification` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in…

  • CVE-2026-10157HigMay 31, 2026
    risk 0.40cvss 7.3epss 0.00

    A vulnerability was identified in Open5GS up to 2.7.6. This impacts an unknown function of the file src/amf/ngap-handler.c of the component NGAP PathSwitchRequest Message Handler. The manipulation leads to improper authentication. It is possible to initiate the attack remotely.…

  • CVE-2025-15555HigFeb 4, 2026
    risk 0.40cvss 7.3epss 0.01

    A security flaw has been discovered in Open5GS up to 2.7.6. Affected by this vulnerability is the function hss_ogs_diam_cx_mar_cb of the file src/hss/hss-cx-path.c of the component VoLTE Cx-Test. The manipulation of the argument OGS_KEY_LEN results in stack-based buffer…

  • CVE-2026-92417MedSep 16, 2026
    risk 0.35cvss 6.5epss 0.01

    A vulnerability was found in Open5GS up to 2.8.0. This affects the function ogs_pfcp_parse_volume_measurement in the library lib/pfcp/types.c of the component PFCP Handler. The manipulation results in null pointer dereference. The attack may be launched remotely. The patch is…

  • CVE-2026-8187MedMay 9, 2026
    risk 0.35cvss 5.3epss 0.01

    A flaw has been found in Open5GS up to 2.7.7. This impacts the function _gtpv1_u_recv_cb of the file src/upf/gtp-path.c of the component UPF. Executing a manipulation can lead to resource consumption. The attack may be performed from remote. The project was informed of the…

Page 3 of 11