CVE-2026-10116

Severity CVSS v4.0:
LOW
Type:
CWE-404 Improper Resource Shutdown or Release
Publication date:
30/05/2026
Last modified:
30/05/2026

Description

A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability affects the function ogs_sbi_xact_add in the library /lib/core/ogs-timer.c of the component ue-authentications Endpoint. Performing a manipulation results in denial of service. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. Applying a patch is the recommended action to fix this issue.