CVE-2026-10117 Details
Description
A weakness has been identified in Open5GS up to 2.7.7. This issue affects the function ogs_pool_id_calloc in the library /lib/sbi/nghttp2-server.c. Executing a manipulation can lead to denial of service. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. It is best practice to apply a patch to resolve this issue.
A denial-of-service vulnerability has been identified in Open5GS versions through 2.7.7. The issue arises in the shared HTTP/2 server used by various Service-Based Interface (SBI) network functions. When a client sends a large number of incomplete HTTP/2 requests, the server exhausts its allocation pools for stream and request management. This leads to a failure in handling incoming request headers, causing the associated network function to crash. The vulnerability can be exploited remotely, and the published exploit demonstrates this impact across all tested Open5GS SBI network functions.
Users are advised to update to Open5GS version 2.7.8 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 30, 2026CISA-ADP
Assessed Jun 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/open5gs/open5gs/ | [email protected] | Vendor |
| https://github.com/open5gs/open5gs/issues/4474 | [email protected] | ExploitIssue TrackingTechnical AnalysisVendor |
| https://vuldb.com/submit/818586 | [email protected] | Permission Required |
| https://vuldb.com/vuln/367295 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/367295/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-404 | Improper Resource Shutdown or Release | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Open5GS | <= 2.7.7 (semver) |
CPE
Remediation
| |
| Open5GS NRF | All versions |
CPE
Remediation
| |
| Open5GS UDM | All versions |
CPE
Remediation
| |
| Open5GS UDR | All versions |
CPE
Remediation
| |
| Open5GS NSSF | All versions |
CPE
Remediation
| |
| Open5GS BSF | All versions |
CPE
Remediation
| |
| Open5GS PCF | All versions |
CPE
Remediation
| |
| Open5GS AMF | All versions |
CPE
Remediation
| |
| Open5GS AUSF | All versions |
CPE
Remediation
| |
| Open5GS SMF | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 30, 2026 | New CVE Received | [email protected] |
Volerion