Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Open5GS — Vulnerabilities & Security Advisories 136

All 136 CVE vulnerabilities found in Open5GS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerabilities associated with the vendor Open5GS, a free and open-source implementation of the 5G core network stack. The collection includes historical security advisories published by the project maintainers, covering known software defects and their corresponding CVE records. Users can utilize this resource to track the vendor's latest security updates, analyze the specific types of implementation errors commonly found in 5G core network components, and review the complete vulnerability history of the Open5GS product to understand its current security posture.

Vendor: unspecified

CVE ID Title CVSS Severity Published
CVE-2026-92417 Open5GS PFCP types.c ogs_pfcp_parse_volume_measurement null pointer dereference CWE-476 6.5 Medium 2026-09-16
CVE-2026-92416 Open5GS PFCP Session Report Request n4-handler.c smf_n4_handle_session_report_request assertion CWE-617 4.3 Medium 2026-09-16
CVE-2026-91855 Open5GS PFCP Message handler.c denial of service CWE-404 5.3 Medium 2026-09-15
CVE-2026-90707 Open5GS Old AMF Discovery Fallback nnrf-handler.c amf_nnrf_try_old_amf_discovery_fallback use after free CWE-416 8.3 High 2026-09-14
CVE-2026-86212 Open5GS AMF/MME improper authorization CWE-285 4.3 Medium 2026-09-06
CVE-2026-82590 Open5GS SMF nudm-handler.c smf_nudm_sdm_handle_get assertion CWE-617 4.3 Medium 2026-08-30
CVE-2026-82589 Open5GS N1-N2 Message namf-handler.c amf_namf_comm_handle_n1_n2_message_transfer denial of service CWE-404 4.3 Medium 2026-08-30
CVE-2026-82588 Open5GS Transfer Endpoint namf-handler.c null pointer dereference CWE-476 4.3 Medium 2026-08-30
CVE-2026-82587 Open5GS AMF namf-handler.c amf_namf_comm_decode_ue_mm_context_list memory corruption CWE-119 4.3 Medium 2026-08-30
CVE-2026-78186 Open5GS HSS hss-cx-path.c assertion CWE-617 4.3 Medium 2026-08-24
CVE-2026-78158 Open5GS AMF UEContextReleaseRequest Path improper authorization CWE-285 6.3 Medium 2026-08-24
CVE-2026-78157 Open5GS Rx AA-Request pcrf-rx-path.c pcrf_rx_aar_cb out-of-bounds CWE-125 7.4 High 2026-08-24
CVE-2026-78156 Open5GS S6a Authentication-Information-Request hss-s6a-path.c hss_ogs_diam_s6a_air_cb heap-based overflow CWE-122 7.4 High 2026-08-23
CVE-2025-15687 Open5GS SMF Diameter Gx Credit-Control-Answer smf_gx_cca_cb denial of service CWE-404 4.3 Medium 2026-08-12
CVE-2025-15686 Open5GS HSS Service fd_msg_sess_get denial of service CWE-404 4.3 Medium 2026-08-12
CVE-2025-15685 Open5GS freeDiameter memory corruption CWE-119 6.3 Medium 2026-08-12
CVE-2025-15684 Open5GS CER init.c diam_log_func assertion CWE-617 5.3 Medium 2026-08-12
CVE-2024-14044 Open5GS Diameter Rx pcrf-rx-path.c pcrf_rx_aar_cb buffer overflow CWE-120 6.3 Medium 2026-08-12
CVE-2024-14043 Open5GS Diameter S6a mme-fd-path.c mme_s6a_subscription_data_from_avp heap-based overflow CWE-122 6.3 Medium 2026-08-11
CVE-2024-14042 Open5GS Diameter S6a hss-s6a-path.c hss_ogs_diam_s6a_ulr_cb stack-based overflow CWE-121 6.3 Medium 2026-08-11
CVE-2026-15720 Pre-auth heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler CWE-125 8.6 High 2026-07-14
CVE-2026-15194 Open5GS AMF context.c amf_context_final use after free CWE-416 3.3 Low 2026-07-09
CVE-2026-14618 Open5GS AMF nnrf-handler.c amf_nnrf_handle_nf_discover denial of service CWE-404 4.3 Medium 2026-07-04
CVE-2026-10565 Open5GS NGAP Handover gmm-sm.c gmm_state_security_mode race condition CWE-362 3.1 Low 2026-06-02
CVE-2026-10157 Open5GS NGAP PathSwitchRequest Message ngap-handler.c improper authentication CWE-287 7.3 High 2026-05-31
CVE-2026-10156 Open5GS nf-instances Endpoint nnrf-handler.c handle_amf_info resource consumption CWE-400 4.3 Medium 2026-05-30
CVE-2026-10117 Open5GS nghttp2-server.c ogs_pool_id_calloc denial of service CWE-404 4.3 Medium 2026-05-30
CVE-2026-10116 Open5GS ue-authentications Endpoint ogs-timer.c ogs_sbi_xact_add denial of service CWE-404 4.3 Medium 2026-05-30
CVE-2026-10115 Open5GS Shared NF-profile nnrf-handler.c denial of service CWE-404 4.3 Medium 2026-05-30
CVE-2026-10114 Open5GS Shared NF-profile nnrf-handler.c handle_scp_info out-of-bounds write CWE-787 4.3 Medium 2026-05-30

All 136 known CVE vulnerabilities affecting Open5GS with full Chinese analysis, references, and POCs where available.