Vulnerability Description
A vulnerability was detected in Open5GS up to 2.7.7. This affects the function ogs_sbi_client_send_via_scp_or_sepp in the library lib/sbi/client.c of the component NF. Performing a manipulation results in out-of-bounds read. The attack is possible to be carried out remotely. The patch is named d5bc487fcf9ea87d2b03f2ef95123af344773bfb. It is suggested to install a patch to address this issue.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Open5Gs | Open5Gs | <= 2.7.7 |
Related Weaknesses (CWE)
References
- https://github.com/open5gs/open5gs/Product
- https://github.com/open5gs/open5gs/commit/d5bc487fcf9ea87d2b03f2ef95123af344773bPatch
- https://github.com/open5gs/open5gs/issues/4491ExploitIssue Tracking
- https://github.com/open5gs/open5gs/pull/4496Issue TrackingPatch
- https://vuldb.com/submit/800024Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/362338Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/362338/ctiPermissions RequiredVDB Entry
- https://github.com/open5gs/open5gs/issues/4491ExploitIssue Tracking
FAQ
What is CVE-2026-8186?
CVE-2026-8186 is a vulnerability with a CVSS score of 5.3 (MEDIUM). A vulnerability was detected in Open5GS up to 2.7.7. This affects the function ogs_sbi_client_send_via_scp_or_sepp in the library lib/sbi/client.c of the component NF. Performing a manipulation result...
How severe is CVE-2026-8186?
CVE-2026-8186 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-8186?
Check the references section above for vendor advisories and patch information. Affected products include: Open5Gs Open5Gs.