CVE-2026-1736

A security vulnerability has been detected in Open5GS up to 2.7.6. Impacted is the function sgwc_s11_handle_create_indirect_data_forwarding_tunnel_request of the file /src/sgwc/s11-handler.c of the component SGWC. Such manipulation leads to reachable assertion. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. A patch should be applied to remediate this issue. The issue report is flagged as already-fixed.
References
Link Resource
https://github.com/open5gs/open5gs/ Product
https://github.com/open5gs/open5gs/issues/4270 Exploit Issue Tracking Vendor Advisory
https://github.com/open5gs/open5gs/issues/4270#event-21968624624 Issue Tracking
https://github.com/open5gs/open5gs/issues/4270#issue-3795141303 Exploit Issue Tracking Vendor Advisory
https://vuldb.com/?ctiid.343635 Permissions Required VDB Entry
https://vuldb.com/?id.343635 Third Party Advisory VDB Entry
https://vuldb.com/?submit.741191 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*

History

11 Feb 2026, 19:34

Type Values Removed Values Added
References () https://github.com/open5gs/open5gs/ - () https://github.com/open5gs/open5gs/ - Product
References () https://github.com/open5gs/open5gs/issues/4270 - () https://github.com/open5gs/open5gs/issues/4270 - Exploit, Issue Tracking, Vendor Advisory
References () https://github.com/open5gs/open5gs/issues/4270#event-21968624624 - () https://github.com/open5gs/open5gs/issues/4270#event-21968624624 - Issue Tracking
References () https://github.com/open5gs/open5gs/issues/4270#issue-3795141303 - () https://github.com/open5gs/open5gs/issues/4270#issue-3795141303 - Exploit, Issue Tracking, Vendor Advisory
References () https://vuldb.com/?ctiid.343635 - () https://vuldb.com/?ctiid.343635 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.343635 - () https://vuldb.com/?id.343635 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.741191 - () https://vuldb.com/?submit.741191 - Third Party Advisory, VDB Entry
CPE cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*
First Time Open5gs open5gs
Open5gs

02 Feb 2026, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-02 01:15

Updated : 2026-02-11 19:34


NVD link : CVE-2026-1736

Mitre link : CVE-2026-1736

CVE.ORG link : CVE-2026-1736


JSON object : View

Products Affected

open5gs

  • open5gs
CWE
CWE-617

Reachable Assertion