Description
A flaw has been found in Open5GS up to 2.8.0. This affects an unknown function of the file src/hss/hss-cx-path.c of the component HSS. This manipulation of the argument User-Name causes reachable assertion. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: c9abe09421eb99bbf1cd7862a3d375e58a4eb9e4. It is recommended to apply a patch to fix this issue.
Published: 2026-08-24
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A bug in Open5GS HSS component hss-cx-path.c allows a remote attacker to send a specially crafted User-Name string that triggers an assertion failure. The resulting assertion failure can crash the HSS service, causing a denial of service and potentially exposing sensitive state before termination. This flaw is identified as a reachable assertion (CWE-617).

Affected Systems

All Open5GS deployments running versions up to and including 2.8.0 are vulnerable. The flaw resides in the HSS component, which is used by the core network to handle subscriber information. Any instance that processes external HSS CX requests is at risk.

Risk and Exploitability

The CVSS score of 5.3 reflects moderate severity; no EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog. Exploit code has been published and the attack can be performed remotely over the control plane network. The lack of an EPSS value does not diminish the risk of denial of service if the flaw remains unpatched, especially in exposed or multi-tenant deployments.

Generated by OpenCVE AI on August 24, 2026 at 05:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Open5GS patch commit c9abe09421eb99bbf1cd7862a3d375e58a4eb9e4 or upgrade to a version newer than 2.8.0.
  • If the patch cannot be applied immediately, restrict access to the HSS service to trusted internal networks or enforce strict ACLs to limit who can send CX requests.
  • Continuously monitor HSS logs for assertion failures or anomalous traffic patterns indicative of exploitation attempts.

Generated by OpenCVE AI on August 24, 2026 at 05:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Open5GS up to 2.8.0. This affects an unknown function of the file src/hss/hss-cx-path.c of the component HSS. This manipulation of the argument User-Name causes reachable assertion. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: c9abe09421eb99bbf1cd7862a3d375e58a4eb9e4. It is recommended to apply a patch to fix this issue.
Title Open5GS HSS hss-cx-path.c assertion
First Time appeared Open5gs
Open5gs open5gs
Weaknesses CWE-617
CPEs cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*
Vendors & Products Open5gs
Open5gs open5gs
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-24T04:15:08.586Z

Reserved: 2026-08-23T16:44:41.636Z

Link: CVE-2026-78186

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-24T05:16:55.277

Modified: 2026-08-24T05:16:55.277

Link: CVE-2026-78186

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T05:30:12Z

Weaknesses