CVE-2026-7707: Open5GS UDR nudr-handler.c udr_nudr_dr_handle_subscription_context denial of service
A vulnerability was found in Open5GS up to 2.7.7. Impacted is the function udrnudrdrhandlesubscriptioncontext of the file /src/udr/nudr-handler.c of the component UDR. The manipulation of the argument pei results in denial of service. The attack can be launched remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7707?
CVE-2026-7707 is classified as a denial of service vulnerability affecting Open5GS UDR.
How do I fix CVE-2026-7707?
To fix CVE-2026-7707, update Open5GS UDR to version 2.7.8 or later.
What versions of Open5GS UDR are affected by CVE-2026-7707?
CVE-2026-7707 affects Open5GS UDR versions up to and including 2.7.7.
What component does CVE-2026-7707 affect within Open5GS?
CVE-2026-7707 affects the UDR component, specifically the udr_nudr_dr_handle_subscription_context function.
What kind of impact does CVE-2026-7707 have?
CVE-2026-7707 can lead to a denial of service condition within the Open5GS UDR system.