LOW 2.1 NVD
CVE-2026-78157
A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the file src/pcrf/pcrf-rx-path.c of the component Rx AA-Request Handl
A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the file src/pcrf/pcrf-rx-path.c of the component Rx AA-Request Handler. Performing a manipulation results in out-of-bounds read. It is possible to initiate the attack remotely. The patch is named c18dc6938bf63cc7374315d3dca303d92066e746. To fix this issue, it is recommended to deploy a patch.
References
- https://github.com/open5gs/open5gs/
- https://github.com/open5gs/open5gs/commit/c18dc6938bf63cc7374315d3dca303d92066e746
- https://github.com/open5gs/open5gs/issues/4663
- https://vuldb.com/cve/CVE-2026-78157
- https://vuldb.com/submit/882953
This low severity vulnerability with a CVSS score of 2.1 was published on 2026-08-24 via NVD.
vulnfeed aggregates 10945 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.