Vulnerability Description
A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the file src/pcrf/pcrf-rx-path.c of the component Rx AA-Request Handler. Performing a manipulation results in out-of-bounds read. It is possible to initiate the attack remotely. The patch is named c18dc6938bf63cc7374315d3dca303d92066e746. To fix this issue, it is recommended to deploy a patch.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/open5gs/open5gs/
- https://github.com/open5gs/open5gs/commit/c18dc6938bf63cc7374315d3dca303d92066e7
- https://github.com/open5gs/open5gs/issues/4663
- https://vuldb.com/cve/CVE-2026-78157
- https://vuldb.com/submit/882953
- https://vuldb.com/vuln/394540
- https://vuldb.com/vuln/394540/cti
- https://github.com/open5gs/open5gs/issues/4663
FAQ
What is CVE-2026-78157?
CVE-2026-78157 is a vulnerability with a CVSS score of 7.4 (HIGH). A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the file src/pcrf/pcrf-rx-path.c of the component Rx AA-Request Handler. Performing a manipulation results in...
How severe is CVE-2026-78157?
CVE-2026-78157 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-78157?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.