Description
A security flaw has been discovered in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality of the file lib/pfcp/handler.c of the component PFCP Message Handler. Performing a manipulation results in denial of service. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The patch is named 028e1dbb5e3271035ccee906ef417a97fc523f71. Applying a patch is the recommended action to fix this issue. CVE-2025-29339 describes a different assertion failure vulnerability in Open5GS UPF.
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A flaw in the Open5GS PFCP Message Handler, specifically in lib/pfcp/handler.c, allows a remote attacker to cause a denial of service by sending a carefully crafted PFCP message. The vulnerability triggers a resource exhaustion or crash in the server component, interrupting service availability. The weakness is classified as CWE-404.

Affected Systems

The vulnerability affects the Open5GS platform, versions up to and including 2.7.7. All stack that have not applied the fix identified by commit 028e1dbb5e3271035ccee906ef417a97fc523f71 are potentially exposed.

Risk and Exploitability

With a CVSS score of 6.9 and an EPSS score of less than 1%, the vulnerability presents a moderate risk. Public exploits have been released, and remote exploitation is possible. An attacker can manipulate network traffic to a PFCP endpoint, triggering a denial of service and potentially disrupting 5G network operations.

Generated by OpenCVE AI on September 20, 2026 at 15:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Open5GS to a version newer than 2.7.7 or apply the patch 028e1dbb5e3271035ccee906ef417a97fc523f71.
  • Apply firewall or ACL rules to restrict PFCP traffic to known, trusted peers.
  • Implement rate limiting or deep‑packet inspection on PFCP traffic to detect and drop malformed messages before they reach the server.

Generated by OpenCVE AI on September 20, 2026 at 15:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality of the file lib/pfcp/handler.c of the component PFCP Message Handler. Performing a manipulation results in denial of service. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The patch is named 028e1dbb5e3271035ccee906ef417a97fc523f71. Applying a patch is the recommended action to fix this issue. CVE-2025-29339 describes a different assertion failure vulnerability in Open5GS UPF.
Title Open5GS PFCP Message handler.c denial of service
First Time appeared Open5gs
Open5gs open5gs
Weaknesses CWE-404
CPEs cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*
Vendors & Products Open5gs
Open5gs open5gs
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T17:44:40.050Z

Reserved: 2026-09-15T09:10:03.977Z

Link: CVE-2026-91855

cve-icon Vulnrichment

Updated: 2026-09-15T17:44:36.555Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T17:17:39.867

Modified: 2026-09-16T13:42:49.240

Link: CVE-2026-91855

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:30:17Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release