CVE-2026-7708
Deferred Deferred - Pending Action
Denial of Service in Open5GS UDR Component

Publication date: 2026-05-03

Last updated on: 2026-05-03

Assigner: VulDB

Description
A vulnerability was determined in Open5GS up to 2.7.7. The affected element is the function ogs_dbi_subscription_data in the library /lib/dbi/subscription.c of the component UDR. This manipulation of the argument supi_id causes denial of service. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-03
Last Modified
2026-05-03
Generated
2026-05-07
AI Q&A
2026-05-04
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
open5gs open5gs to 2.7.7 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-404 The product does not release or incorrectly releases a resource before it is made available for re-use.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in Open5GS up to version 2.7.7, specifically in the function ogs_dbi_subscription_data within the UDR component's subscription.c library. It involves manipulation of the argument supi_id, which can cause a denial of service condition. The attack can be initiated remotely, and the exploit has been publicly disclosed.


How can this vulnerability impact me? :

The vulnerability can lead to a denial of service (DoS) condition, which means that the affected system or service may become unavailable or unresponsive. Since the attack can be initiated remotely, it poses a risk of service disruption without requiring physical access.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart