CVE-2026-78186
Received Received - Intake

Open5GS Assertion Failure via User-Name Manipulation

Vulnerability report for CVE-2026-78186, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: VulDB

Description

A flaw has been found in Open5GS up to 2.8.0. This affects an unknown function of the file src/hss/hss-cx-path.c of the component HSS. This manipulation of the argument User-Name causes reachable assertion. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: c9abe09421eb99bbf1cd7862a3d375e58a4eb9e4. It is recommended to apply a patch to fix this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
open5gs open5gs to 2.8.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-617 The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a flaw in Open5GS up to version 2.8.0 affecting the HSS component. It involves a reachable assertion triggered by manipulating the User-Name argument in Diameter protocol messages. The issue occurs when an empty User-Name is used as a hash key, causing the HSS to terminate unexpectedly. A patch has been released to address this.

Detection Guidance

Monitor HSS logs for assertion failures or crashes in Open5GS. Check for malformed Diameter Cx protocol messages with empty User-Name fields. Use network traffic analysis tools like Wireshark to inspect Diameter MAR/SAR messages for invalid AVP values.

Impact Analysis

This vulnerability can lead to a denial-of-service condition where the HSS process crashes, disrupting core network services. Attackers can remotely exploit it by sending a single malformed request with an empty User-Name, causing the HSS to abort. This impacts availability of 5G core network functions.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling denial-of-service (DoS) attacks against the Home Subscriber Server (HSS) in Open5GS. A successful exploit may cause the HSS to terminate unexpectedly, disrupting core network operations and potentially leading to unauthorized access or data processing interruptions. GDPR requires ensuring availability and integrity of personal data, while HIPAA mandates continuous access to critical systems. A DoS condition may violate these requirements.

Mitigation Strategies

Apply the patch from commit c9abe09421eb99bbf1cd7862a3d375e58a4eb9e4. Update Open5GS to a version that includes input validation for User-Name and Public-Identity fields in Diameter messages. Temporarily block malformed Diameter requests at the network perimeter if patching is not immediately possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78186. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart