VulnSea

Osmocom has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 7.5 (high).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
4 prev 0

Products

  • libsmpp34 1
  • osmo-bsc 1
  • osmo-ggsn 1
  • osmo-iuh 1
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

Osmocom vulnerabilities

CVEs affecting Osmocom, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-75895High· 7.5
3d ago

In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was found in the at smpp34_unpack() function via attacker controlled SMPP PDUs, leading to memory corruption.

In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was found in the at smpp34_unpack() function via attacker controlled SMPP PDUs, leading to memory corruption.

TwilightOsmocom · libsmpp34EPSS 0.16%via NVD
CVE-2026-75894High· 7.5
3d ago

In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt() function via a arbitrarily sized NAS-PDU that leads to process crash and remote denial of service.

In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt() function via a arbitrarily sized NAS-PDU that leads to process crash and remote denial of service.

TwilightOsmocom · osmo-iuhEPSS 0.17%via NVD
CVE-2026-75893High· 7.5
3d ago

In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the ipaccess_proxy_read_msg()  function via IPA frame lengths.

In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the ipaccess_proxy_read_msg()  function via IPA frame lengths.

TwilightOsmocom · osmo-bscEPSS 0.14%via NVD
CVE-2026-75892Medium· 6.5
3d ago

In osmo-ggsn 1.14.0 an out of bounds write issue was found in the gtp_decode_pdp_ctx() function through the PDP context GSN-Address sub-field, leading to memory corruption.

In osmo-ggsn 1.14.0 an out of bounds write issue was found in the gtp_decode_pdp_ctx() function through the PDP context GSN-Address sub-field, leading to memory corruption.

SunlitOsmocom · osmo-ggsnEPSS 0.14%via NVD
Osmocom vulnerabilities (CVEs) · VulnSea