{"id":"CVE-2026-108102","title":"Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_volume_measurement() in lib/pfcp/types.c that allows remote unauthenticated attackers to read past IE buffers","summary":"Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_volume_measurement() in lib/pfcp/types.c that allows remote unauthenticated attackers to read past IE buffers. Attackers can send a PFCP Session Rep…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-125"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T15:17:10.997","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-108102","references":[{"url":"https://github.com/open5gs/open5gs","label":"disclosure@vulncheck.com"},{"url":"https://github.com/open5gs/open5gs/blob/v2.8.0/lib/pfcp/types.c#L581-L635","label":"disclosure@vulncheck.com"},{"url":"https://github.com/open5gs/open5gs/commit/88e64fc1f87e0d321364b3bb710ef6a8f274e568","label":"disclosure@vulncheck.com"},{"url":"https://github.com/open5gs/open5gs/security/advisories/GHSA-37c3-hv4f-688p","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/open5gs-through-2.8.0-heap-out-of-bounds-read-via-pfcp-volume-measurement-ie","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"ingestedAt":"2026-10-09T16:02:33.378Z","slug":"CVE-2026-108102","body":"## Overview\n\nOpen5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_volume_measurement() in lib/pfcp/types.c that allows remote unauthenticated attackers to read past IE buffers. Attackers can send a PFCP Session Report Request to the SMF on UDP port 8805 with a short, all-flags Volume Measurement IE, reading up to 48 bytes and potentially crashing the SMF.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}