Remote Denial of Service Vulnerability in Open5GS Software
CVE-2026-92416

5.3MEDIUM

Key Information:

Vendor

Open5GS

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92416?

A remote Denial of Service vulnerability exists in Open5GS versions up to 2.8.0, specifically in the PFCP Session Report Request Handler. The vulnerability is triggered during the execution of the function smf_n4_handle_session_report_request located in the file src/smf/n4-handler.c, leading to a condition where assertions can be reached. To mitigate the risk associated with this vulnerability, it is recommended that users upgrade to the patched version, identified by the commit e5f0c06d0f2d9613b003daa1cfa3ba8a4bd157e9.

Affected Version(s)

Open5GS 2.0

Open5GS 2.1

Open5GS 2.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

WeiYi (VulDB User)
.