CVE-2026-1586: Open5GS SGWC s11-handler.c ogs_gtp2_f_teid_to_ip denial of service
Published Jan 29, 2026
·Updated
A flaw has been found in Open5GS up to 2.7.5. Impacted is the function ogsgtp2fteidtoip of the file /sgwc/s11-handler.c of the component SGWC. Executing a manipulation can lead to denial of service. The attack may be performed from remote. The exploit has been published and may be used. It is advisable to implement a patch to correct this issue. The issue report is flagged as already-fixed.
Affected Software
2 affected components
Open5GS<=2.7.5
open5gs open5gs<2.7.6
Event History
Jan 29, 2026
CVE Published
via MITRE·12:32 PM
Data Sourced
via MITRE·12:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Dec 12, 58060
Event
via NVD·08:12 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-1586?
CVE-2026-1586 is classified as a denial of service vulnerability.
2
How do I fix CVE-2026-1586?
To fix CVE-2026-1586, update Open5GS to a version later than 2.7.5.
3
What components are affected by CVE-2026-1586?
CVE-2026-1586 affects the SGWC component in Open5GS.
4
Is CVE-2026-1586 exploitable remotely?
Yes, CVE-2026-1586 can be exploited remotely to cause a denial of service.
5
Which versions of Open5GS are vulnerable to CVE-2026-1586?
Open5GS versions up to and including 2.7.5 are vulnerable to CVE-2026-1586.