CVE-2026-1586: OPEN5GS
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
A flaw has been found in Open5GS up to 2.7.5. Impacted is the function ogs_gtp2_f_teid_to_ip of the file /sgwc/s11-handler.c of the component SGWC. Executing a manipulation can lead to denial of service. The attack may be performed from remote. The exploit has been published and may be used. It is advisable to implement a patch to correct this issue. The issue report is flagged as already-fixed.
Affected products
- OPEN5GS OPEN5GS: before 2.7.6 (fixed in 2.7.6)
Published 2026-01-29. Last modified 2026-06-17.