Reachable Assertion Vulnerability in Open5GS MME
CVE-2026-108105

8.2HIGH

Key Information:

Vendor

Open5gs

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-108105?

Open5GS version 2.8.0 contains a reachable assertion vulnerability within the mme_gn_handle_sgsn_context_request() function. This flaw enables remote, unauthenticated attackers to exploit malformed SGSN Address Information Elements (IEs). By sending GTPv1-C traffic from a configured SGSN address using a known user equipment (UE) IMSI or P-TMSI, an attacker can provide an invalid address length, causing the open5gs-mmed process to crash. This vulnerability could lead to service disruptions for all subscribers connected to the affected MME.

Affected Version(s)

open5gs 0 <= 2.8.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tristan Madani
.