A weakness has been identified in Open5GS up to 2.7.7. This issue affects the function ogs_pool_id_calloc in the library /lib/sbi/nghttp2-server.c. Executing a manipulation can lead to denial of service. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. It is best practice to apply a patch to resolve this issue.
Metrics
Affected Vendors & Products
References
History
Sat, 30 May 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in Open5GS up to 2.7.7. This issue affects the function ogs_pool_id_calloc in the library /lib/sbi/nghttp2-server.c. Executing a manipulation can lead to denial of service. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. It is best practice to apply a patch to resolve this issue. | |
| Title | Open5GS nghttp2-server.c ogs_pool_id_calloc denial of service | |
| First Time appeared |
Open5gs
Open5gs open5gs |
|
| Weaknesses | CWE-404 | |
| CPEs | cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Open5gs
Open5gs open5gs |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-05-30T12:30:08.160Z
Reserved: 2026-05-29T17:15:20.897Z
Link: CVE-2026-10117
No data.
Status : Received
Published: 2026-05-30T13:16:20.870
Modified: 2026-05-30T13:16:20.870
Link: CVE-2026-10117
No data.
OpenCVE Enrichment
Updated: 2026-05-30T13:30:24Z