CVE-2026-8226: Open5GS types.c ogs_pcc_rule_install_flow_from_media denial of service
A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability affects the function ogspccruleinstallflowfrommedia in the library /lib/proto/types.c. The manipulation results in denial of service. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Open5GSto a version that resolves this vulnerability.Fixed in 2.7.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8226?
CVE-2026-8226 is considered a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2026-8226?
To fix CVE-2026-8226, you should upgrade Open5GS to version 2.7.8 or later.
What versions of Open5GS are affected by CVE-2026-8226?
Open5GS versions up to and including 2.7.7 are affected by CVE-2026-8226.
What type of vulnerability is CVE-2026-8226?
CVE-2026-8226 is categorized as a denial of service vulnerability.
What function is involved in CVE-2026-8226?
The vulnerability in CVE-2026-8226 involves the function ogs_pcc_rule_install_flow_from_media in the Open5GS library.