CVE-2026-8187Disclosure(open5gs / open5gs)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in Open5GS up to 2.7.7. This impacts the function _gtpv1_u_recv_cb of the file src/upf/gtp-path.c of the component UPF. Executing a manipulation can lead to resource consumption. The attack may be performed from remote. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-404

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • open5gs

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-05-09); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
open5gs

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-09: 3Mentions · 2026-05-11: 1Technical Details · 2026-05-09: 2Technical Details · 2026-05-11: 105-0905-11
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-093
Disclosure2General1
2026-05-111
Disclosure1
Full discourse4 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-8187 📊 Severity: 5.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-8187 #CVE-2026-8187 #CVE #Medium #CyberSecurity #InfoSec https://t.co/oL36aws2AQ

    Post summary

    The tweet announces the new CVE‑2026‑8187 with a medium severity rating (CVSS 5.3) but provides no evidence of exploitation, patch, or PoC details.

    0000037
    158 followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    📉 Open5GS (≤ 2.7.7) vulnerable to remote resource exhaustion in UPF component via crafted GTP traffic. #CVE #5G #DoS https://nvd.nist.gov/vuln/detail/CVE-2026-8187

    Post summary

    Open5GS versions ≤2.7.7 are vulnerable to remote resource exhaustion in the UPF component through crafted GTP traffic, potentially resulting in a denial‑of‑service.

    00000140
    1.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-8187 A flaw has been found in Open5GS up to 2.7.7. This impacts the function _gtpv1_u_recv_cb of the file src/upf/gtp-path.c of the component UPF. Executing a manipulation c… https://www.cve.org/CVERecord?id=CVE-2026-8187

    Post summary

    A flaw in Open5GS up to version 2.7.7 is disclosed, affecting the _gtpv1_u_recv_cb function in src/upf/gtp-path.c, without providing PoC, exploit code, patch information, or evidence of active exploitation.

    00000194
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-8187 Resource Consumption Vulnerability in Open5GS UPF Up to Version 2.7.7 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8187

    Post summary

    The content merely announces a CVE with minimal details, lacking PoC, exploit, patch, or active usage information.

    00000302
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopen5gsopen5gs---

Explore more