CVE-2026-8187
גבוהה 7.5
תיאור (מקור, אנגלית)
A flaw has been found in Open5GS up to 2.7.7. This impacts the function _gtpv1_u_recv_cb of the file src/upf/gtp-path.c of the component UPF. Executing a manipulation can lead to resource consumption. The attack may be performed from remote. The project was informed of the problem early through an issue report but has not responded yet.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - CVSS 4.0
-
6.9 (MEDIUM)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 1% (אחוזון 000) נכון ל-2/8/2026
- CWE
- CWE-400, CWE-404
מוצרים מושפעים
open5gs: open5gs
קישורים
- https://github.com/open5gs/open5gs/issues/4492 ExploitIssue Tracking
- https://github.com/open5gs/open5gs/issues/4492 ExploitIssue Tracking
- https://github.com/open5gs/open5gs/ Product
- https://vuldb.com/submit/800025 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/362339 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/362339/cti Permissions RequiredVDB Entry