CVE-2026-107166

medium

Description

A weakness has been identified in Open5GS up to 2.7.7. This vulnerability affects the function ogs_pfcp_xact_local_create of the file src/upf/gtp-path.c of the component GTP-U Receive Path. This manipulation causes allocation of resources. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Patch name: 9ffc252482d9b03ac01abcedbe95497ff4f95dd0. It is recommended to apply a patch to fix this issue.

References

https://vuldb.com/vuln/414968/cti

https://vuldb.com/vuln/414968

https://vuldb.com/submit/994175

https://vuldb.com/cve/CVE-2026-107166

https://github.com/open5gs/open5gs/pull/4806

https://github.com/open5gs/open5gs/issues/4792

https://github.com/open5gs/open5gs/commit/9ffc252482d9b03ac01abcedbe95497ff4f95dd0

https://github.com/open5gs/open5gs/

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-94412

Details

Source: Mitre, NVD

Published: 2026-10-07

Updated: 2026-10-07

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 5.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Severity: Medium

CVSS v4

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00552