CVE-2026-8186
Severity CVSS v4.0:
MEDIUM
Type:
CWE-119
Buffer Errors
Publication date:
09/05/2026
Last modified:
13/05/2026
Description
A vulnerability was detected in Open5GS up to 2.7.7. This affects the function ogs_sbi_client_send_via_scp_or_sepp in the library lib/sbi/client.c of the component NF. Performing a manipulation results in out-of-bounds read. The attack is possible to be carried out remotely. The patch is named d5bc487fcf9ea87d2b03f2ef95123af344773bfb. It is suggested to install a patch to address this issue.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:* | 2.7.7 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/open5gs/open5gs/
- https://github.com/open5gs/open5gs/commit/d5bc487fcf9ea87d2b03f2ef95123af344773bfb
- https://github.com/open5gs/open5gs/issues/4491
- https://github.com/open5gs/open5gs/pull/4496
- https://vuldb.com/submit/800024
- https://vuldb.com/vuln/362338
- https://vuldb.com/vuln/362338/cti
- https://github.com/open5gs/open5gs/issues/4491



