Description
A weakness has been identified in Open5GS up to 2.7.7. This vulnerability affects the function ogs_pfcp_xact_local_create of the file src/upf/gtp-path.c of the component GTP-U Receive Path. This manipulation causes allocation of resources. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Patch name: 9ffc252482d9b03ac01abcedbe95497ff4f95dd0. It is recommended to apply a patch to fix this issue.
Published: 2026-10-07
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Resource Exhaustion / Denial of Service
Action: Immediate Patch
AI Analysis

Impact

Open5GS is a software implementation for 5G core networks. A flaw in the GTP‑U receive path, specifically the function ogs_pfcp_xact_local_create in src/upf/gtp-path.c, allows an attacker to cause uncontrolled allocation of resources. This can lead to exhaustion of memory or other system resources, potentially causing the UPF module to crash or become unusable. The weakness corresponds to CWE‑400 and CWE‑770, indicating unbounded resource consumption and failure to handle memory allocation errors.

Affected Systems

Affected vendor is Open5GS (cpe:2.3:a:open5gs:open5gs). The issue exists in all releases up to and including version 2.7.7. Any user running 2.7.7 or earlier is vulnerable. The affected component is the GTP‑U Receive Path within the UPF service of the Open5GS stack.

Risk and Exploitability

The CVSS score of 6.9 indicates medium severity; the EPSS score is not available, but the vulnerability has been made public and the exploit is known, meaning that remote attackers can target exposed UPF instances. The flaw is not yet listed in the CISA KEV catalogue, but the combination of medium severity and publicly available exploitation code elevates the risk for environments with a 5G core exposed to untrusted traffic. Attackers can leverage simple crafted GTP‑U packets to spike resource usage and trigger denial of service.

Generated by OpenCVE AI on October 7, 2026 at 17:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the upstream patch commit 9ffc252482d9b03ac01abcedbe95497ff4f95dd0 or upgrade to Open5GS 2.7.8 or later.
  • Restrict inbound GTP‑U traffic to trusted peers using firewall or ACL rules to prevent malicious packet injection.
  • Monitor system memory and UPF process resource usage, and consider applying hard limits or cgroup restrictions to contain potential exhaustion.

Generated by OpenCVE AI on October 7, 2026 at 17:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Open5GS up to 2.7.7. This vulnerability affects the function ogs_pfcp_xact_local_create of the file src/upf/gtp-path.c of the component GTP-U Receive Path. This manipulation causes allocation of resources. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Patch name: 9ffc252482d9b03ac01abcedbe95497ff4f95dd0. It is recommended to apply a patch to fix this issue.
Title Open5GS GTP-U Receive Path gtp-path.c ogs_pfcp_xact_local_create allocation of resources
First Time appeared Open5gs
Open5gs open5gs
Weaknesses CWE-400
CWE-770
CPEs cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*
Vendors & Products Open5gs
Open5gs open5gs
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-07T16:00:09.165Z

Reserved: 2026-10-07T11:26:59.363Z

Link: CVE-2026-107166

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-07T16:17:44.870

Modified: 2026-10-07T16:17:45.053

Link: CVE-2026-107166

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T17:45:14Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-770

    Allocation of Resources Without Limits or Throttling