CVE-2026-7707

medium

Description

A vulnerability was found in Open5GS up to 2.7.7. Impacted is the function udr_nudr_dr_handle_subscription_context of the file /src/udr/nudr-handler.c of the component UDR. The manipulation of the argument pei results in denial of service. The attack can be launched remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

References

https://vuldb.com/vuln/360883/cti

https://vuldb.com/vuln/360883

https://vuldb.com/submit/805700

https://vuldb.com/submit/805699

https://github.com/open5gs/open5gs/issues/4411

https://github.com/open5gs/open5gs/issues/4410

https://github.com/open5gs/open5gs/

Details

Source: Mitre, NVD

Published: 2026-05-03

Updated: 2026-05-03

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Severity: Medium

CVSS v4

Base Score: 5.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00057