Executive brief
Open5GS is an open-source implementation of 5G and 4G mobile core networks. A flaw in its User Plane Function (UPF) component allows a remote attacker to overwhelm the system with malicious network traffic. This can cause severe performance degradation, leading to dropped connections and making the mobile network unusable for legitimate users.
Technical details
A vulnerability exists in the Open5GS User Plane Function (UPF) within the GTP-U packet receiving callback (_gtpv1_u_recv_cb in src/upf/gtp-path.c). The component performs expensive synchronous operations, such as detailed logging and generating error responses, directly on the high-speed data path when processing malformed or abusive GTP-U packets (e.g., Echo Requests or invalid TEIDs). A remote, unauthenticated attacker can exploit this by sending a high-rate stream of such packets, exhausting CPU resources and starving the forwarding loop. This results in significant latency spikes and packet loss for legitimate user-plane traffic. As of the advisory date, the project has not yet released a formal patch.
Affected products
- Open5GS Open5GS up to 2.7.7
Timeline
- 2026-04-25: disclosed: Issue reported to the project maintainers via GitHub
- 2026-05-09: advisory: Vulnerability published by VulDB/NVD