CVE-2026-7708
Denial of Service in Open5GS UDR Component
Publication date: 2026-05-03
Last updated on: 2026-05-03
Assigner: VulDB
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| open5gs | open5gs | to 2.7.7 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-404 | The product does not release or incorrectly releases a resource before it is made available for re-use. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in Open5GS up to version 2.7.7, specifically in the function ogs_dbi_subscription_data within the UDR component's subscription.c library. It involves manipulation of the argument supi_id, which can cause a denial of service condition. The attack can be initiated remotely, and the exploit has been publicly disclosed.
How can this vulnerability impact me? :
The vulnerability can lead to a denial of service (DoS) condition, which means that the affected system or service may become unavailable or unresponsive. Since the attack can be initiated remotely, it poses a risk of service disruption without requiring physical access.