OPEN5GS
162 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for OPEN5GS, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.
OPEN5GS CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 2 |
| 2024-12 | 0 |
| 2025-01 | 29 |
| 2025-02 | 1 |
| 2025-03 | 3 |
| 2025-04 | 1 |
| 2025-05 | 0 |
| 2025-06 | 6 |
| 2025-07 | 2 |
| 2025-08 | 9 |
| 2025-09 | 3 |
| 2025-10 | 2 |
| 2025-11 | 1 |
| 2025-12 | 5 |
| 2026-01 | 14 |
| 2026-02 | 10 |
| 2026-03 | 2 |
| 2026-04 | 0 |
| 2026-05 | 45 |
| 2026-06 | 0 |
| 2026-07 | 1 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 162 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical3
- High49
- Medium98
- Low12
Latest CVEs
The 15 most recently published vulnerabilities affecting OPEN5GS.
- CVE-2026-15720Pre-auth heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler8.6
- CVE-2026-10157Open5GS NGAP PathSwitchRequest Message ngap-handler.c improper authentication7.3
- CVE-2026-10156Open5GS nf-instances Endpoint nnrf-handler.c handle_amf_info resource consumption4.3
- CVE-2026-10117Open5GS nghttp2-server.c ogs_pool_id_calloc denial of service4.3
- CVE-2026-10116Open5GS ue-authentications Endpoint ogs-timer.c ogs_sbi_xact_add denial of service4.3
- CVE-2026-10115Open5GS Shared NF-profile nnrf-handler.c denial of service4.3
- CVE-2026-10114Open5GS Shared NF-profile nnrf-handler.c handle_scp_info out-of-bounds write4.3
- CVE-2026-10113Open5GS Shared NF-profile nnrf-handler.c denial of service4.3
- CVE-2026-8746Open5GS NRF nghttp2-server.c discover_handler use after free4.3
- CVE-2026-8745Open5GS AUSF nausf-handler.c ogs_timer_add denial of service4.3
- CVE-2026-8744Open5GS NRF context.c ogs_sbi_nf_service_add denial of service4.3
- CVE-2026-8743Open5GS AMF/MME context.c ran_ue_find_by_amf_ue_ngap_id improper authorization6.3
- CVE-2026-8731Open5GS NRF client.c ogs_sbi_client_add denial of service4.3
- CVE-2026-8730Open5GS NRF context.c ogs_sbi_nf_instance_set_id denial of service4.3
- CVE-2026-8729Open5GS NRF message.c denial of service4.3
Product grouping is registry-driven, with AI assist and human review. How it works