GTP-U Receive Path Vulnerability in Open5GS by Open5GS
CVE-2026-107166
Key Information:
Badges
What is CVE-2026-107166?
A vulnerability has been reported in Open5GS versions up to 2.7.7 in the GTP-U Receive Path function ogs_pfcp_xact_local_create, which allows remote attackers to manipulate resource allocations. This issue can potentially be exploited without authentication, making it critical to address. Users are advised to apply the provided patch (commit 9ffc252482d9b03ac01abcedbe95497ff4f95dd0) to safeguard against potential exploits, as the attack vector has been publicly disclosed.
Affected Version(s)
Open5GS 2.7.0
Open5GS 2.7.1
Open5GS 2.7.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
