CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-107166: Open5GS 2.7.0, 2.7.1, 2.7.2, 2.7.3, 2.7.4, 2.7.5, 2.7.6, 2.7.7

CVE-2026-107166. CVSS 2.0 base score 5.0 (MEDIUM, Vendor/CNA).

Affected technology

Open5GS · 2.7.0, 2.7.1, 2.7.2, 2.7.3, 2.7.4, 2.7.5, 2.7.6, 2.7.7
Vendor not specified by the source

Description’s affected range: up to 2.7.7

Component: GTP-U Receive Path
Function: ogs_pfcp_xact_local_create
File: src/upf/gtp-path.c

Attack conditions (VulDB, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

VulDB’s CVSS 4.0 assessment (base score 5.5/10) rates confidentiality and integrity impact as none; availability impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

Patch identifier: 9ffc252482d9b03ac01abcedbe95497ff4f95dd0

Published

CWE
CWE-400, CWE-770
CCR priority
20.0 /100 (P4)
CVSS 2.0
5.0 /10 · CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:N/A:P · Vendor/CNA
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-107166.html