Get real-time updates on Telegram
CVE-2026-107166: Open5GS 2.7.0, 2.7.1, 2.7.2, 2.7.3, 2.7.4, 2.7.5, 2.7.6, 2.7.7
CVE-2026-107166. CVSS 2.0 base score 5.0 (MEDIUM, Vendor/CNA).
Affected technology
Open5GS · 2.7.0, 2.7.1, 2.7.2, 2.7.3, 2.7.4, 2.7.5, 2.7.6, 2.7.7
Vendor not specified by the source
Description’s affected range: up to 2.7.7
Component: GTP-U Receive Path
Function: ogs_pfcp_xact_local_create
File: src/upf/gtp-path.c
Attack conditions (VulDB, CVSS 4.0): Network (remote) · No privileges required · No user interaction required
What an attacker can do
VulDB’s CVSS 4.0 assessment (base score 5.5/10) rates confidentiality and integrity impact as none; availability impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.
Patch identifier: 9ffc252482d9b03ac01abcedbe95497ff4f95dd0
- CWE
- CWE-400, CWE-770
- CCR priority
- 20.0 /100 (P4)
- CVSS 2.0
- 5.0 /10 · CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:N/A:P · Vendor/CNA
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-07 18:01:36.740415+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-107166.html