CVE-2026-1738: Open5GS SGWC context.c sgwc_tunnel_add assertion
A flaw has been found in Open5GS up to 2.7.6. The impacted element is the function sgwctunneladd of the file /src/sgwc/context.c of the component SGWC. Executing a manipulation of the argument pdr can lead to reachable assertion. The attack can be executed remotely. The exploit has been published and may be used. It is advisable to implement a patch to correct this issue. The issue report is flagged as already-fixed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1738?
CVE-2026-1738 is classified as a medium severity vulnerability due to the potential for an attacker to trigger a reachable assertion.
How do I fix CVE-2026-1738?
To remediate CVE-2026-1738, update Open5GS to a version later than 2.7.6 that addresses this vulnerability.
What systems are affected by CVE-2026-1738?
CVE-2026-1738 affects Open5GS versions up to and including 2.7.6.
What actions can lead to CVE-2026-1738 being exploited?
CVE-2026-1738 can be exploited by manipulating the argument pdr in the sgwc_tunnel_add function.
Is there a workaround for CVE-2026-1738?
Currently, there is no documented workaround for CVE-2026-1738; upgrading to a patched version is recommended.