---
id: CVE-2026-108103
title: >-
  Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in
  ogs_pfcp_parse_dropped_dl_traffic_threshold() that allows remote
  unauthenticated attackers to read past IE buffers via short IEs
summary: >-
  Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in
  ogs_pfcp_parse_dropped_dl_traffic_threshold() that allows remote
  unauthenticated attackers to read past IE buffers via short IEs. Attackers can
  send PFCP Session E…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-125
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T15:17:11.163'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-108103'
references:
  - url: 'https://github.com/open5gs/open5gs'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/open5gs/open5gs/blob/v2.8.0/lib/pfcp/types.c#L484-L516'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/open5gs/open5gs/commit/88e64fc1f87e0d321364b3bb710ef6a8f274e568
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/open5gs-through-2.8.0-heap-out-of-bounds-read-via-pfcp-dropped-dl-traffic-threshold-ie
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-10-09T16:02:33.379Z'
---

## Overview

Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_dropped_dl_traffic_threshold() that allows remote unauthenticated attackers to read past IE buffers via short IEs. Attackers can send PFCP Session Establishment or Modification Requests to the UPF on UDP port 8805 with DLPA and DLBY flags set, potentially crashing the UPF.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
