CVE-2026-78156: Heap-based Buffer Overflow in Open5GS
Description
CVE-2026-78156 is a heap-based buffer overflow vulnerability in Open5GS version 2.8.0. It affects the function hss_ogs_diam_s6a_air_cb in the S6a Authentication-Information-Request Handler component. The vulnerability arises from improper handling of the Visited-PLMN-Id argument, which can be manipulated remotely to trigger the overflow. A patch identified by commit a9c82ee0b590d76a581b0580cb46b598984e2392 is available to remediate this issue.
CVSS v4.0
Score 5.3medium
Affected software
Open5GS
cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in Open5GS 2.8.0 involves a heap-based buffer overflow in the function hss_ogs_diam_s6a_air_cb located in src/hss/hss-s6a-path.c. The flaw is triggered by manipulation of the Visited-PLMN-Id argument in the S6a Authentication-Information-Request Handler, allowing a remote attacker to cause memory corruption. The issue has been addressed by a patch identified by the commit hash a9c82ee0b590d76a581b0580cb46b598984e2392.
Potential Impact
Successful exploitation of this vulnerability could lead to memory corruption due to heap-based buffer overflow, potentially resulting in denial of service or other undefined behavior. The CVSS 4.0 score is 5.3 (medium severity), indicating a moderate risk with remote attack vector and low complexity.
Mitigation Recommendations
A patch is available for Open5GS version 2.8.0, identified by commit a9c82ee0b590d76a581b0580cb46b598984e2392. Users should apply this patch to remediate the vulnerability. No additional vendor advisory content is provided, so patch status is confirmed by the presence of the patch commit.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-08-23T11:34:31.832Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8b87c6acd9273b498a2150
Added to database: 08/23/2026, 23:52:38 UTC
Last enriched: 09/10/2026, 23:18:00 UTC
Last updated: 10/06/2026, 06:48:20 UTC
Views: 74
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.