CVE-2026-82590
- EPSS 0.31%
- Veröffentlicht 30.08.2026 22:30:11
- Zuletzt bearbeitet 31.08.2026 22:17:25
A weakness has been identified in Open5GS up to 2.7.7. The affected element is the function smf_nudm_sdm_handle_get of the file src/smf/nudm-handler.c of the component SMF. Executing a manipulation of the argument preemptCap can lead to reachable ass...
CVE-2026-82588
- EPSS 0.31%
- Veröffentlicht 30.08.2026 22:17:00
- Zuletzt bearbeitet 01.09.2026 15:17:33
A vulnerability was identified in Open5GS up to 2.7.7. This issue affects some unknown processing of the file src/amf/namf-handler.c of the component Transfer Endpoint. Such manipulation leads to null pointer dereference. The attack can be launched r...
CVE-2026-82589
- EPSS 0.31%
- Veröffentlicht 30.08.2026 22:15:11
- Zuletzt bearbeitet 31.08.2026 20:56:08
A security flaw has been discovered in Open5GS up to 2.7.7. Impacted is the function amf_namf_comm_handle_n1_n2_message_transfer of the file src/amf/namf-handler.c of the component N1-N2 Message Handler. Performing a manipulation of the argument N1N2...
CVE-2026-82587
- EPSS 0.31%
- Veröffentlicht 30.08.2026 19:00:11
- Zuletzt bearbeitet 31.08.2026 20:56:08
A vulnerability was determined in Open5GS up to 2.7.7. This vulnerability affects the function amf_namf_comm_decode_ue_mm_context_list of the file src/amf/namf-handler.c of the component AMF. This manipulation of the argument ueContext.mmContextList[...
CVE-2026-30045
- EPSS 0.18%
- Veröffentlicht 27.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 20:59:32
An integer overflow in the /nnrf-disc/v1/nf-instances component of open5gs v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted HTTP/2 GET request.
CVE-2026-30046
- EPSS 0.32%
- Veröffentlicht 27.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 20:12:02
A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.
CVE-2026-30047
- EPSS 0.32%
- Veröffentlicht 27.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 20:12:02
A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.
CVE-2026-37198
- EPSS 0.45%
- Veröffentlicht 27.08.2026 00:00:00
- Zuletzt bearbeitet 09.09.2026 16:04:24
An integer overflow in the SMF component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted GTP packet.
CVE-2026-78186
- EPSS 0.39%
- Veröffentlicht 24.08.2026 05:16:55
- Zuletzt bearbeitet 24.08.2026 16:41:13
A flaw has been found in Open5GS up to 2.8.0. This affects an unknown function of the file src/hss/hss-cx-path.c of the component HSS. This manipulation of the argument User-Name causes reachable assertion. The attack is possible to be carried out re...
CVE-2026-78157
- EPSS 0.23%
- Veröffentlicht 24.08.2026 01:16:56
- Zuletzt bearbeitet 24.08.2026 18:17:25
A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the file src/pcrf/pcrf-rx-path.c of the component Rx AA-Request Handler. Performing a manipulation results in out-of-bounds read. It is possible to initiate th...