Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/newplane/open5gs

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

0

CVE-2026-78186 is a medium severity vulnerability in Open5GS up to version 2.8.0. It involves a reachable assertion flaw in the HSS component, specifically in the src/hss/hss-cx-path.c file. The vulnerability is triggered by manipulation of the User-Name argument and can be exploited remotely. An exploit has been published. A patch identified by commit c9abe09421eb99bbf1cd7862a3d375e58a4eb9e4 is available to fix this issue.

Join the discussion

A vulnerability in Open5GS 2.8.0 affects the Rx AA-Request Handler component, specifically the function pcrf_rx_aar_cb. This vulnerability allows a remote attacker to cause an out-of-bounds read by manipulating input. The issue is identified as CVE-2026-78157 and has a CVSS score of 7.4. A patch has been created to address this vulnerability, but no explicit patch link or vendor advisory is provided in the data.

Join the discussion

Open5GS version 2.8.0 contains a heap-based buffer overflow vulnerability in the S6a Authentication-Information-Request Handler component. The flaw exists in the function hss_ogs_diam_s6a_air_cb when processing the Visited-PLMN-Id argument. This vulnerability can be exploited remotely and may lead to partial confidentiality, integrity, and availability impact. A patch identified by commit a9c82ee0b590d76a581b0580cb46b598984e2392 addresses this issue.

Join the discussion
0

CVE-2026-78158 is a medium severity vulnerability in Open5GS version 2.8.0 involving improper authorization in the AMF UEContextReleaseRequest Path Handler component. The flaw allows remote attackers with low privileges to manipulate the system, potentially bypassing authorization controls. No patch or vendor advisory is currently provided, and no known exploits are reported in the wild.

Join the discussion
0

CVE-2026-78157 is an out-of-bounds read vulnerability in Open5GS version 2.8.0 affecting the pcrf_rx_aar_cb function in the Rx AA-Request Handler component. The vulnerability can be triggered remotely by manipulating input to this function. A patch has been identified to fix this issue.

Join the discussion
0

CVE-2026-78156 is a heap-based buffer overflow vulnerability in Open5GS version 2.8.0. It affects the function hss_ogs_diam_s6a_air_cb in the S6a Authentication-Information-Request Handler component. The vulnerability arises from improper handling of the Visited-PLMN-Id argument, which can be manipulated remotely to trigger the overflow. A patch identified by commit a9c82ee0b590d76a581b0580cb46b598984e2392 is available to remediate this issue.

Join the discussion

Open5GS version 2.7.0 contains a vulnerability in the ngap_send_to_nas() function within src/amf/ngap-path.c that allows a remote attacker to cause a denial of service. This issue is identified as CVE-2026-71675 and is classified with a high severity score of 7.5. The vulnerability does not impact confidentiality or integrity but affects availability by enabling denial of service. There is no information about patches or fixes currently available. No known exploits are reported in the wild at this time.

Join the discussion

A buffer overflow vulnerability exists in Open5GS version 2.7.0 that can be triggered remotely via the NAS 5GS decoder chain. The flaw occurs when the message type byte of a NAS PDU is mutated, allowing an attacker to cause a denial of service condition.

Join the discussion

A buffer overflow vulnerability exists in Open5GS up to version 2.7.1 in the Diameter Rx Handler component, specifically in the pcrf_rx_aar_cb function. This flaw is caused by improper handling of the arguments num_of_media_component and num_of_sub. The vulnerability can be exploited remotely. A public exploit is available. Upgrading to version 2.7.2 addresses this issue.

Join the discussion
0

A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb of the component SMF Diameter Gx Credit-Control-Answer Handler. The manipulation results in denial of service. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.7.7 is recommended to address this issue. The patch is identified as f23d7a5e959acd8f37b925dc29b85f26b7d391cb. Upgrading the affected component is advised.

Join the discussion

Showing 1 to 10 of 114 results

Filters:Package: pkg:github/newplane/open5gs
Page 1 of 12
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses