CVE-2026-108103
Deferred Deferred - Pending Action

Heap Out-of-Bounds Read in Open5GS UPF

Vulnerability report for CVE-2026-108103, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: VulnCheck

Description

Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_dropped_dl_traffic_threshold() that allows remote unauthenticated attackers to read past IE buffers via short IEs. Attackers can send PFCP Session Establishment or Modification Requests to the UPF on UDP port 8805 with DLPA and DLBY flags set, potentially crashing the UPF.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
open5gs open5gs 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Open5GS through version 2.8.0 has a heap out-of-bounds read flaw in the function ogs_pfcp_parse_dropped_dl_traffic_threshold(). This occurs when short Information Elements (IEs) are processed, allowing attackers to read memory beyond allocated buffers. Exploiters can send specially crafted PFCP Session Establishment or Modification Requests to the UPF on UDP port 8805 with DLPA and DLBY flags enabled, potentially causing the UPF to crash.

Detection Guidance

Detect this vulnerability by monitoring UPF crashes or unusual traffic patterns on UDP port 8805. Check Open5GS logs for heap out-of-bounds read errors. Use network traffic analysis tools like tcpdump or Wireshark to inspect PFCP Session Establishment or Modification Requests with DLPA and DLBY flags set.

Impact Analysis

This vulnerability allows remote unauthenticated attackers to crash the UPF component of Open5GS, disrupting network services. If exploited, it could lead to denial-of-service conditions, affecting the availability of the network infrastructure.

Mitigation Strategies

Upgrade Open5GS to a version later than 2.8.0 to patch the heap out-of-bounds read vulnerability. If immediate upgrading is not possible, restrict access to UDP port 8805 using firewall rules to limit exposure to potential attackers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108103. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart