CVE-2026-92417

A vulnerability was found in Open5GS up to 2.8.0. This affects the function ogs_pfcp_parse_volume_measurement in the library lib/pfcp/types.c of the component PFCP Handler. The manipulation results in null pointer dereference. The attack may be launched remotely. The patch is identified as 8f07b507b78ff94776f2cd49276eb116ed93d7f2. A patch should be applied to remediate this issue.

  • Published Sep 16, 2026
  • CVSS 7.1 high
  • 0.7% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-92417 at the National Vulnerability Database