---
id: CVE-2026-8226
title: A security flaw has been discovered in Open5GS up to 2.7.7
summary: >-
  A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability
  affects the function ogs_pcc_rule_install_flow_from_media in the library
  /lib/proto/types.c. The manipulation results in denial of service. The attack
  can be …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-404
vendor: open5gs
product: open5gs
affected:
  - open5gs <= 2.7.7
published: '2026-05-10'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-8226'
references:
  - url: 'https://github.com/open5gs/open5gs/'
    label: cna@vuldb.com
  - url: 'https://github.com/open5gs/open5gs/issues/4441'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/808445'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/362443'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/362443/cti'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.0085
epssPercentile: 0.56362
ingestedAt: '2026-07-24T07:21:21.014Z'
---

## Overview

A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability affects the function ogs_pcc_rule_install_flow_from_media in the library /lib/proto/types.c. The manipulation results in denial of service. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

## Affected

- `open5gs <= 2.7.7`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
