CVE-2026-8186: Open5GS NF client.c ogs_sbi_client_send_via_scp_or_sepp out-of-bounds
A vulnerability was detected in Open5GS up to 2.7.7. This affects the function ogssbiclientsendviascporsepp in the library lib/sbi/client.c of the component NF. Performing a manipulation results in out-of-bounds read. The attack is possible to be carried out remotely. The patch is named d5bc487fcf9ea87d2b03f2ef95123af344773bfb. It is suggested to install a patch to address this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Open5GSto a version that resolves this vulnerability.Patch d5bc487fcf9ea87d2b03f2ef95123af344773bfb
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8186?
CVE-2026-8186 is classified as a high severity vulnerability due to potential out-of-bounds read exploits.
How do I fix CVE-2026-8186?
To fix CVE-2026-8186, update Open5GS to version 2.7.8 or later which addresses the vulnerability.
What components are affected by CVE-2026-8186?
CVE-2026-8186 affects the NF component specifically within the open5gs library lib/sbi/client.c.
What types of attacks can CVE-2026-8186 facilitate?
CVE-2026-8186 can facilitate out-of-bounds read attacks that may lead to information disclosure or application instability.
What versions of Open5GS are impacted by CVE-2026-8186?
Open5GS versions up to and including 2.7.7 are impacted by CVE-2026-8186.