open5gs has 13 CVEs on record. Disclosures have slowed: 0 in the last 90 days after 13 in the 90 before. The busiest recent month was May 2026 with 13. The median CVSS is 4.3 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-404 (13).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.3
- Publish → KEV
- —
- Last 90 days
- 0 prev 13
Weakness classes
Products
- open5gs 13
Worst active — by depth score
CVE-2026-8226Medium· 5.3A security flaw has been discovered in Open5GS up to 2.7.729CVE-2026-8225Medium· 5.3A vulnerability was identified in Open5GS up to 2.7.729CVE-2026-8224Medium· 5.3A vulnerability was determined in Open5GS up to 2.7.729CVE-2026-8223Medium· 5.3A vulnerability was found in Open5GS up to 2.7.729CVE-2026-8222Medium· 5.3A vulnerability has been found in Open5GS up to 2.7.729
open5gs vulnerabilities
CVEs affecting open5gs, newest first. Open any entry for full detail, references, and exploit status.
13 CVEsRSS
CVE-2026-8252Medium· 4.3A vulnerability was determined in Open5GS up to 2.7.7
A vulnerability was determined in Open5GS up to 2.7.7. Affected is the function smf_nsmf_handle_create_data_in_hsmf of the component SMF. Executing a manipulation can lead to null pointer dereference. The attack may be performed from rem…
CVE-2026-8268Medium· 4.3A vulnerability has been found in Open5GS up to 2.7.7
A vulnerability has been found in Open5GS up to 2.7.7. This issue affects the function OpenAPI_list_create of the component SMF. Such manipulation leads to denial of service. The attack may be launched remotely. The exploit has been disc…
CVE-2026-8267Medium· 4.3A flaw has been found in Open5GS up to 2.7.7
A flaw has been found in Open5GS up to 2.7.7. This vulnerability affects the function smf_nsmf_handle_created_data_in_vsmf of the component SMF. This manipulation causes denial of service. The attack may be initiated remotely. The exploi…
CVE-2026-8266Medium· 4.3A vulnerability was detected in Open5GS up to 2.7.7
A vulnerability was detected in Open5GS up to 2.7.7. This affects the function gsm_build_pdu_session_establishment_accept of the file /src/smf/gsm-build.c of the component SMF. The manipulation results in denial of service. The attack ca…
CVE-2026-8251Medium· 4.3A vulnerability was found in Open5GS up to 2.7.7
A vulnerability was found in Open5GS up to 2.7.7. This impacts the function update_authorized_pcc_rule_and_qos of the file /src/smf/npcf-handler.c of the component SMF. Performing a manipulation results in denial of service. The attack i…
CVE-2026-8250Medium· 4.3A vulnerability has been found in Open5GS up to 2.7.7
A vulnerability has been found in Open5GS up to 2.7.7. This affects the function smf_n4_build_qos_flow_to_modify_list of the file /src/smf/n4-build.c of the component SMF. Such manipulation leads to denial of service. The attack can be e…
CVE-2026-8249Medium· 4.3A flaw has been found in Open5GS up to 2.7.7
A flaw has been found in Open5GS up to 2.7.7. The impacted element is the function update_authorized_pcc_rule_and_qos of the file /src/smf/npcf-handler.c of the component SMF. This manipulation causes denial of service. Remote exploitati…
CVE-2026-8248Medium· 4.3A vulnerability was detected in Open5GS up to 2.7.7
A vulnerability was detected in Open5GS up to 2.7.7. The affected element is the function update_authorized_pcc_rule_and_qos of the file /src/smf/npcf-handler.c of the component SMF. The manipulation results in denial of service. The att…
CVE-2026-8226Medium· 5.3A security flaw has been discovered in Open5GS up to 2.7.7
A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability affects the function ogs_pcc_rule_install_flow_from_media in the library /lib/proto/types.c. The manipulation results in denial of service. The attack can be …
CVE-2026-8225Medium· 5.3A vulnerability was identified in Open5GS up to 2.7.7
A vulnerability was identified in Open5GS up to 2.7.7. This affects the function pcf_npcf_smpolicycontrol_handle_delete of the file src/pcf/sm-sm.c of the component delete Endpoint. The manipulation leads to denial of service. The attack…
CVE-2026-8224Medium· 5.3A vulnerability was determined in Open5GS up to 2.7.7
A vulnerability was determined in Open5GS up to 2.7.7. Affected by this issue is the function pcf_sess_set_ipv6prefix of the file /src/pcf/context.c of the component PCF. Executing a manipulation of the argument SmPolicyContextData.ipv6A…
CVE-2026-8223Medium· 5.3A vulnerability was found in Open5GS up to 2.7.7
A vulnerability was found in Open5GS up to 2.7.7. Affected by this vulnerability is the function pcf_sess_sbi_discover_and_send of the component sm-policies Endpoint. Performing a manipulation results in denial of service. It is possible…
CVE-2026-8222Medium· 5.3A vulnerability has been found in Open5GS up to 2.7.7
A vulnerability has been found in Open5GS up to 2.7.7. Affected is the function pcf_nbsf_management_handle_register of the file src/pcf/nbsf-handler.c of the component sm-policies Endpoint. Such manipulation leads to denial of service. T…