CVE-2026-107166
Deferred
Deferred - Pending Action
Heap Overflow in Open5GS GTP-U Receive Path
Vulnerability report for CVE-2026-107166, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-07
Last updated on: 2026-10-07
Assigner: VulDB
Description
Description
A weakness has been identified in Open5GS up to 2.7.7. This vulnerability affects the function ogs_pfcp_xact_local_create of the file src/upf/gtp-path.c of the component GTP-U Receive Path. This manipulation causes allocation of resources. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Patch name: 9ffc252482d9b03ac01abcedbe95497ff4f95dd0. It is recommended to apply a patch to fix this issue.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| n/a | Open5GS | 2.7.0 |
| n/a | Open5GS | 2.7.1 |
| n/a | Open5GS | 2.7.2 |
| n/a | Open5GS | 2.7.3 |
| n/a | Open5GS | 2.7.4 |
| n/a | Open5GS | 2.7.5 |
| n/a | Open5GS | 2.7.6 |
| n/a | Open5GS | 2.7.7 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-400 | The product does not properly control the allocation and maintenance of a limited resource. |
| CWE-770 | The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated. |