CVE-2026-2062
- EPSS 0.65%
- Veröffentlicht 06.02.2026 18:32:08
- Zuletzt bearbeitet 11.02.2026 19:02:06
A vulnerability was identified in Open5GS up to 2.7.6. This affects the function sgwc_s5c_handle_modify_bearer_response/sgwc_sxa_handle_session_modification_response of the component PGW S5U Address Handler. The manipulation leads to null pointer der...
CVE-2025-15555
- EPSS 0.52%
- Veröffentlicht 04.02.2026 20:32:07
- Zuletzt bearbeitet 07.04.2026 16:16:22
A security flaw has been discovered in Open5GS up to 2.7.6. Affected by this vulnerability is the function hss_ogs_diam_cx_mar_cb of the file src/hss/hss-cx-path.c of the component VoLTE Cx-Test. The manipulation of the argument OGS_KEY_LEN results i...
CVE-2026-1738
- EPSS 0.66%
- Veröffentlicht 02.02.2026 01:32:07
- Zuletzt bearbeitet 11.02.2026 19:34:54
A flaw has been found in Open5GS up to 2.7.6. The impacted element is the function sgwc_tunnel_add of the file /src/sgwc/context.c of the component SGWC. Executing a manipulation of the argument pdr can lead to reachable assertion. The attack can be ...
CVE-2026-1737
- EPSS 0.49%
- Veröffentlicht 02.02.2026 01:02:07
- Zuletzt bearbeitet 11.02.2026 19:34:45
A vulnerability was detected in Open5GS up to 2.7.6. The affected element is the function sgwc_s5c_handle_create_bearer_request of the file /src/sgwc/s5c-handler.c of the component CreateBearerRequest Handler. Performing a manipulation results in rea...
CVE-2026-1736
- EPSS 0.61%
- Veröffentlicht 02.02.2026 00:32:06
- Zuletzt bearbeitet 11.02.2026 19:34:35
A security vulnerability has been detected in Open5GS up to 2.7.6. Impacted is the function sgwc_s11_handle_create_indirect_data_forwarding_tunnel_request of the file /src/sgwc/s11-handler.c of the component SGWC. Such manipulation leads to reachable...
CVE-2026-1587
- EPSS 0.51%
- Veröffentlicht 29.01.2026 12:32:08
- Zuletzt bearbeitet 23.02.2026 09:16:59
A vulnerability has been found in Open5GS up to 2.7.6. The affected element is the function sgwc_s11_handle_modify_bearer_request of the file /sgwc/s11-handler.c of the component SGWC. The manipulation leads to denial of service. It is possible to in...
CVE-2026-1586
- EPSS 0.51%
- Veröffentlicht 29.01.2026 12:32:06
- Zuletzt bearbeitet 23.02.2026 09:16:59
A flaw has been found in Open5GS up to 2.7.5. Impacted is the function ogs_gtp2_f_teid_to_ip of the file /sgwc/s11-handler.c of the component SGWC. Executing a manipulation can lead to denial of service. The attack may be performed from remote. The e...
CVE-2026-1522
- EPSS 0.66%
- Veröffentlicht 28.01.2026 16:32:07
- Zuletzt bearbeitet 23.02.2026 09:16:57
A weakness has been identified in Open5GS up to 2.7.6. This vulnerability affects the function sgwc_s5c_handle_modify_bearer_response of the file src/sgwc/s5c-handler.c of the component SGWC. Executing a manipulation can lead to denial of service. Th...
CVE-2026-1521
- EPSS 0.51%
- Veröffentlicht 28.01.2026 14:32:10
- Zuletzt bearbeitet 23.02.2026 09:16:56
A security flaw has been discovered in Open5GS up to 2.7.6. This affects the function sgwc_s5c_handle_bearer_resource_failure_indication of the file src/sgwc/s5c-handler.c of the component SGWC. Performing a manipulation results in denial of service....
CVE-2026-0622
- EPSS 0.42%
- Veröffentlicht 20.01.2026 19:56:04
- Zuletzt bearbeitet 03.02.2026 21:38:57
Open 5GS WebUI uses a hard-coded JWT signing key (change-me) whenever the environment variable JWT_SECRET_KEY is unset