Vulnerability Description
An integer overflow in the SMF component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted GTP packet.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://gist.github.com/hackeryounow/b1b6475d9c1d9b2bd1f1ef895d1f298c
- https://github.com/hackeryounow/5GCVulDB/tree/main/CVE-2026-37198
- https://github.com/open5gs/open5gs/issues/4277
- https://github.com/open5gs/open5gs/issues/4278
FAQ
What is CVE-2026-37198?
CVE-2026-37198 is a vulnerability with a CVSS score of 7.5 (HIGH). An integer overflow in the SMF component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted GTP packet.
How severe is CVE-2026-37198?
CVE-2026-37198 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-37198?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.