CVE-2026-108105 PUBLISHED

Open5GS through 2.8.0 MME Reachable Assertion via GTPv1 SGSN Context Request

Assigner: VulnCheck
Reserved: 09.10.2026 Published: 09.10.2026 Updated: 09.10.2026

Open5GS through 2.8.0 contains a reachable assertion vulnerability in mme_gn_handle_sgsn_context_request() that allows remote unauthenticated attackers to crash the MME via malformed SGSN Address IEs. Attackers sending GTPv1-C traffic from a configured SGSN address with a known UE IMSI or P-TMSI can supply an invalid address length to terminate open5gs-mmed, denying service to all subscribers.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.2

Product Status

Vendor open5gs
Product open5gs
Versions Default: unaffected
  • affected from 0 to 2.8.0 (incl.)

Credits

  • Tristan Madani finder

References

Problem Types

  • Reachable Assertion CWE