Open5gs / Open5GS
155 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-92417 | Open5GS PFCP types.c ogs_pfcp_parse_volume_measurement null pointer dereference | HIGH | 7.1 | Sep 16, 2026 |
| CVE-2026-92416 | Open5GS PFCP Session Report Request n4-handler.c smf_n4_handle_session_report_request assertion | MEDIUM | 5.3 | Sep 16, 2026 |
| CVE-2026-91855 | Open5GS PFCP Message handler.c denial of service | MEDIUM | 6.9 | Sep 15, 2026 |
| CVE-2026-90707 | Open5GS Old AMF Discovery Fallback nnrf-handler.c amf_nnrf_try_old_amf_discovery_fallback use after free | MEDIUM | 6.9 | Sep 14, 2026 |
| CVE-2026-86212 | Open5GS AMF/MME improper authorization | MEDIUM | 5.3 | Sep 6, 2026 |
| CVE-2026-82590 | Open5GS SMF nudm-handler.c smf_nudm_sdm_handle_get assertion | MEDIUM | 5.3 | Aug 30, 2026 |
| CVE-2026-82589 | Open5GS N1-N2 Message namf-handler.c amf_namf_comm_handle_n1_n2_message_transfer denial of service | MEDIUM | 5.3 | Aug 30, 2026 |
| CVE-2026-82588 | Open5GS Transfer Endpoint namf-handler.c null pointer dereference | MEDIUM | 5.3 | Aug 30, 2026 |
| CVE-2026-82587 | Open5GS AMF namf-handler.c amf_namf_comm_decode_ue_mm_context_list memory corruption | MEDIUM | 5.3 | Aug 30, 2026 |
| CVE-2026-78186 | Open5GS HSS hss-cx-path.c assertion | MEDIUM | 5.3 | Aug 24, 2026 |
| CVE-2026-78158 | Open5GS AMF UEContextReleaseRequest Path improper authorization | MEDIUM | 5.3 | Aug 24, 2026 |
| CVE-2026-78157 | Open5GS Rx AA-Request pcrf-rx-path.c pcrf_rx_aar_cb out-of-bounds | MEDIUM | 5.3 | Aug 24, 2026 |
| CVE-2026-78156 | Open5GS S6a Authentication-Information-Request hss-s6a-path.c hss_ogs_diam_s6a_air_cb heap-based overflow | MEDIUM | 5.3 | Aug 23, 2026 |
| CVE-2025-15687 | Open5GS SMF Diameter Gx Credit-Control-Answer smf_gx_cca_cb denial of service | MEDIUM | 5.3 | Aug 12, 2026 |
| CVE-2025-15686 | Open5GS HSS Service fd_msg_sess_get denial of service | MEDIUM | 5.3 | Aug 12, 2026 |
| CVE-2025-15685 | Open5GS freeDiameter memory corruption | MEDIUM | 5.3 | Aug 12, 2026 |
| CVE-2025-15684 | Open5GS CER init.c diam_log_func assertion | MEDIUM | 6.9 | Aug 12, 2026 |
| CVE-2024-14044 | Open5GS Diameter Rx pcrf-rx-path.c pcrf_rx_aar_cb buffer overflow | MEDIUM | 5.3 | Aug 12, 2026 |
| CVE-2024-14043 | Open5GS Diameter S6a mme-fd-path.c mme_s6a_subscription_data_from_avp heap-based overflow | MEDIUM | 5.3 | Aug 11, 2026 |
| CVE-2024-14042 | Open5GS Diameter S6a hss-s6a-path.c hss_ogs_diam_s6a_ulr_cb stack-based overflow | MEDIUM | 5.3 | Aug 11, 2026 |
| CVE-2026-15720 | Pre-auth heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler | HIGH | 8.6 | Jul 14, 2026 |
| CVE-2026-15194 | Open5GS AMF context.c amf_context_final use after free | MEDIUM | 4.8 | Jul 9, 2026 |
| CVE-2026-14618 | Open5GS AMF nnrf-handler.c amf_nnrf_handle_nf_discover denial of service | MEDIUM | 5.3 | Jul 4, 2026 |
| CVE-2026-10565 | Open5GS NGAP Handover gmm-sm.c gmm_state_security_mode race condition | LOW | 2.3 | Jun 2, 2026 |
| CVE-2026-10157 | Open5GS NGAP PathSwitchRequest Message ngap-handler.c improper authentication | MEDIUM | 6.9 | May 31, 2026 |
Showing 1 to 25 of 155 CVEs