A security flaw has been discovered in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality of the file lib/pfcp/handler.c of the component PFCP Message Handler. Performing a manipulation results in denial of service. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The patch is named 028e1dbb5e3271035ccee906ef417a97fc523f71. Applying a patch is the recommended action to fix this issue. CVE-2025-29339 describes a different assertion failure vulnerability in Open5GS UPF.
{
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-404"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91855.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "2.7.3"
},
{
"last_affected": "2.7.3"
},
{
"introduced": "2.7.4"
},
{
"last_affected": "2.7.4"
}
],
"source": "AFFECTED_FIELD"
}
]
}{
"extracted_events": [
{
"introduced": "2.7.0"
},
{
"last_affected": "2.7.0"
},
{
"introduced": "2.7.1"
},
{
"last_affected": "2.7.1"
},
{
"introduced": "2.7.2"
},
{
"last_affected": "2.7.2"
},
{
"introduced": "2.7.5"
},
{
"last_affected": "2.7.5"
},
{
"introduced": "2.7.6"
},
{
"last_affected": "2.7.6"
},
{
"introduced": "2.7.7"
},
{
"last_affected": "2.7.7"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-91855.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "230545453255873729189827836366960241647",
"length": 744
},
"id": "CVE-2026-91855-0e67bc66",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/028e1dbb5e3271035ccee906ef417a97fc523f71",
"target": {
"file": "lib/pfcp/context.c",
"function": "ogs_pfcp_setup_pdr_gtpu_node"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "254319519912905455462299230538024998175",
"length": 4292
},
"id": "CVE-2026-91855-1f25bd3a",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/028e1dbb5e3271035ccee906ef417a97fc523f71",
"target": {
"file": "src/sgwu/sxa-handler.c",
"function": "sgwu_sxa_handle_session_modification_request"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "126489484860550904453564432690787272139",
"length": 4987
},
"id": "CVE-2026-91855-4ca55328",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/028e1dbb5e3271035ccee906ef417a97fc523f71",
"target": {
"file": "src/upf/n4-handler.c",
"function": "upf_n4_handle_session_modification_request"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "210090259689515600951236313722871421002",
"length": 4078
},
"id": "CVE-2026-91855-52b6632f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/028e1dbb5e3271035ccee906ef417a97fc523f71",
"target": {
"file": "src/upf/n4-handler.c",
"function": "upf_n4_handle_session_establishment_request"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"326343499815558128090961952471220455110",
"268454131294937335444603814139258982509",
"276091957610795965994776802693919891078",
"307091394461657070776238610901722595079"
],
"threshold": 0.9
},
"id": "CVE-2026-91855-7b697355",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/028e1dbb5e3271035ccee906ef417a97fc523f71",
"target": {
"file": "src/sgwu/sxa-handler.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"309474640871951335070823968950859545292",
"82602333344607486654006609607252086258",
"164020309649031385095752972422973768260",
"240285105475084501070949595922154754684",
"309474640871951335070823968950859545292",
"82602333344607486654006609607252086258",
"164020309649031385095752972422973768260",
"240285105475084501070949595922154754684"
],
"threshold": 0.9
},
"id": "CVE-2026-91855-9a99efa2",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/028e1dbb5e3271035ccee906ef417a97fc523f71",
"target": {
"file": "lib/pfcp/context.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "212299393228737724976784488861918411591",
"length": 2392
},
"id": "CVE-2026-91855-a5e83405",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/028e1dbb5e3271035ccee906ef417a97fc523f71",
"target": {
"file": "lib/pfcp/handler.c",
"function": "ogs_pfcp_handle_create_far"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "241144325863279876339122522060877818981",
"length": 657
},
"id": "CVE-2026-91855-a8bbc7de",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/028e1dbb5e3271035ccee906ef417a97fc523f71",
"target": {
"file": "lib/pfcp/context.c",
"function": "ogs_pfcp_setup_far_gtpu_node"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"137724495931723198850055789331741743073",
"88783401803101748053881006623844741796",
"108657516588713475212328728068102050809",
"31434271374179997559153935999751768083",
"28615813239261532732994134129636992332",
"288067726668032505297611147897858213650",
"62170415614142711629619224000791229578",
"168408139644031092740684784916896283042",
"312711795957172146392856098943283027364",
"329615666235087495452115722048443336738",
"143166375258817315960414397611828728374",
"17853520726974668369536903805102068343",
"186400941776807863431172556265364296191",
"226451177130252279789909150631376291334",
"325685008024968204826317052991207942051",
"315136655843945200505381941788937890435",
"62726077703516887068027324794521097704",
"203525722170605199220521857480373440045",
"203456631922506332840281207396348427070",
"142207365057600856894623286805361623812",
"295651741198405335237177432815584841979",
"334980467557475235968050876426850812168",
"78563920018197662207235029018707345622",
"30410721011809447722916163307448523532",
"168408139644031092740684784916896283042",
"312711795957172146392856098943283027364",
"329615666235087495452115722048443336738",
"143166375258817315960414397611828728374",
"17853520726974668369536903805102068343",
"186400941776807863431172556265364296191",
"226451177130252279789909150631376291334",
"325685008024968204826317052991207942051",
"315136655843945200505381941788937890435",
"62726077703516887068027324794521097704",
"203525722170605199220521857480373440045",
"203456631922506332840281207396348427070",
"142207365057600856894623286805361623812",
"295651741198405335237177432815584841979"
],
"threshold": 0.9
},
"id": "CVE-2026-91855-ca3f4598",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/028e1dbb5e3271035ccee906ef417a97fc523f71",
"target": {
"file": "lib/pfcp/handler.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"270178608898049280600493865307654661348",
"243509394819193703705020878439989244056",
"304952245024023898305818353672803241504",
"307091394461657070776238610901722595079",
"270178608898049280600493865307654661348",
"243509394819193703705020878439989244056",
"304952245024023898305818353672803241504",
"307091394461657070776238610901722595079"
],
"threshold": 0.9
},
"id": "CVE-2026-91855-cd2a1fea",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/028e1dbb5e3271035ccee906ef417a97fc523f71",
"target": {
"file": "src/upf/n4-handler.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "336749403839023334325156493536652064967",
"length": 2179
},
"id": "CVE-2026-91855-e7d354bc",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/open5gs/open5gs/commit/028e1dbb5e3271035ccee906ef417a97fc523f71",
"target": {
"file": "lib/pfcp/handler.c",
"function": "ogs_pfcp_handle_update_far"
}
}
]
"2026-09-18T08:10:18Z"