---
id: CVE-2026-108102
title: >-
  Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in
  ogs_pfcp_parse_volume_measurement() in lib/pfcp/types.c that allows remote
  unauthenticated attackers to read past IE buffers
summary: >-
  Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in
  ogs_pfcp_parse_volume_measurement() in lib/pfcp/types.c that allows remote
  unauthenticated attackers to read past IE buffers. Attackers can send a PFCP
  Session Rep…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-125
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T15:17:10.997'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-108102'
references:
  - url: 'https://github.com/open5gs/open5gs'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/open5gs/open5gs/blob/v2.8.0/lib/pfcp/types.c#L581-L635'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/open5gs/open5gs/commit/88e64fc1f87e0d321364b3bb710ef6a8f274e568
    label: disclosure@vulncheck.com
  - url: 'https://github.com/open5gs/open5gs/security/advisories/GHSA-37c3-hv4f-688p'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/open5gs-through-2.8.0-heap-out-of-bounds-read-via-pfcp-volume-measurement-ie
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-10-09T16:02:33.378Z'
---

## Overview

Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_volume_measurement() in lib/pfcp/types.c that allows remote unauthenticated attackers to read past IE buffers. Attackers can send a PFCP Session Report Request to the SMF on UDP port 8805 with a short, all-flags Volume Measurement IE, reading up to 48 bytes and potentially crashing the SMF.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
