Skip to main content
Vulnerability Database/CVE-2026-91855

CVE-2026-91855: Open5GS PFCP Handler DOS Vulnerability

CVE-2026-91855 is a denial of service vulnerability in Open5GS PFCP Message Handler that allows remote attackers to disrupt network operations. This post covers the technical details, affected versions, and mitigation steps.

Published:

CVE-2026-91855 Overview

CVE-2026-91855 is a denial-of-service vulnerability affecting Open5GS versions up to and including 2.7.7. The flaw resides in the Packet Forwarding Control Protocol (PFCP) Message Handler, specifically within lib/pfcp/handler.c. An attacker can send a crafted PFCP message over the network to trigger the condition, resulting in loss of service availability on the affected 5G core component. The issue is tracked under [CWE-404: Improper Resource Shutdown or Release]. Exploit code has been published, and a fix is available in commit 028e1dbb5e3271035ccee906ef417a97fc523f71.

Critical Impact

Remote, unauthenticated attackers can disrupt Open5GS core network functions by sending malformed PFCP traffic, degrading availability of 5G control-plane services.

Affected Products

  • Open5GS versions up to 2.7.7
  • Open5GS PFCP Message Handler component (lib/pfcp/handler.c)
  • Deployments using the affected Open5GS User Plane Function (UPF) and Session Management Function (SMF)

Discovery Timeline

  • 2026-09-15 - CVE-2026-91855 published to NVD
  • 2026-09-16 - Last updated in NVD database

Technical Details for CVE-2026-91855

Vulnerability Analysis

Open5GS is an open-source implementation of the 5G Core and EPC. The affected code path processes PFCP messages exchanged between control-plane functions such as the SMF and user-plane functions such as the UPF or SGW-U. When the handler processes a specially crafted PFCP message, an assertion or improper resource-release condition occurs, terminating the process. Because PFCP is exposed on the network interface between core network functions, the failure translates into a full outage of the affected node. A related but distinct assertion failure in Open5GS UPF is tracked as CVE-2025-29339.

Root Cause

The root cause is improper validation of state when handling Outer Header Creation information in Create/Update Forwarding Action Rule (FAR) messages. When ogs_gtp_connect() fails, the node remains in gtpu_peer_list with ogs_sa_family == 0. A subsequent lookup via ogs_gtp_node_find_by_ip() returns this partially initialized node, and ogs_pfcp_far_f_teid_hash_set() aborts with a fatal Unknown family(0) error. This matches [CWE-404], where a resource is not properly released or cleaned up on failure.

Attack Vector

Exploitation requires network reachability to the PFCP interface of an Open5GS control-plane or user-plane function. No authentication or user interaction is required. An attacker that can inject PFCP messages, either from a compromised peer or an exposed management network, can trigger the abort condition and take the affected function offline.

c
// Patch: lib/pfcp/context.c — remove orphaned GTP node on connect failure
                ogs_gtp_self()->gtpu_sock, ogs_gtp_self()->gtpu_sock6, gnode);
        if (rv != OGS_OK) {
            ogs_error("ogs_gtp_connect() failed");
            /*
             * ogs_gtp_node_new() zeroes gnode->addr, and only a successful
             * ogs_gtp_connect() fills it in. On failure the node stays in
             * gtpu_peer_list with ogs_sa_family == 0, so the next request
             * carrying the same IP address finds it through
             * ogs_gtp_node_find_by_ip(), skips ogs_gtp_connect() entirely
             * and reaches ogs_pfcp_far_f_teid_hash_set(), which aborts:
             *
             *   [pfcp] FATAL: Unknown family(0) (../lib/pfcp/context.c)
             *
             * OGS_SETUP_GTP_NODE() has not run yet, so no FAR references
             * this node and removing it here is safe.
             */
            ogs_gtp_node_remove(&ogs_gtp_self()->gtpu_peer_list, gnode);
            return rv;
        }
    }

Source: GitHub Commit 028e1dbb

Detection Methods for CVE-2026-91855

Indicators of Compromise

  • Fatal log entries containing [pfcp] FATAL: Unknown family(0) originating from lib/pfcp/context.c
  • Repeated crashes or restarts of the Open5GS SMF, UPF, or SGW-U process
  • PFCP Create FAR or Update FAR messages carrying Outer Header Creation elements from unexpected source addresses

Detection Strategies

  • Monitor Open5GS service logs for abort messages and unexpected process termination tied to PFCP handling
  • Inspect PFCP traffic captures for malformed or unsolicited Create/Update FAR messages sent to core network functions
  • Alert on repeated ogs_gtp_connect() failed errors preceding fatal aborts

Monitoring Recommendations

  • Ingest Open5GS logs into a centralized logging or SIEM platform and create rules for PFCP fatal error strings
  • Track uptime metrics for SMF, UPF, and SGW-U processes and alert on unexpected restarts
  • Capture and baseline PFCP peer relationships so that traffic from unauthorized IPs is flagged promptly

How to Mitigate CVE-2026-91855

Immediate Actions Required

  • Update Open5GS to a version that includes commit 028e1dbb5e3271035ccee906ef417a97fc523f71 or later
  • Restrict network access to PFCP interfaces so that only trusted core network functions can reach them
  • Review Open5GS deployments exposed to untrusted networks and place them behind segmentation controls

Patch Information

The fix is provided in Open5GS commit 028e1dbb5e3271035ccee906ef417a97fc523f71, titled [PFCP] Validate Outer Header Creation in Create/Update FAR. The patch removes the orphaned GTP node from gtpu_peer_list when ogs_gtp_connect() fails and returns OGS_PFCP_CAUSE_SYSTEM_FAILURE when ogs_pfcp_setup_far_gtpu_node() fails in src/sgwu/sxa-handler.c. Full details are available at the GitHub Commit Details and GitHub Issue #4699.

Workarounds

  • Enforce firewall rules that permit PFCP (UDP/8805) traffic only from authorized peers
  • Deploy network segmentation so that PFCP interfaces are unreachable from user-plane or external networks
  • Enable process supervision (systemd, container orchestrator) to automatically restart failed Open5GS services while a patch is scheduled
bash
# Example: restrict PFCP (UDP/8805) to trusted SMF peer using iptables
iptables -A INPUT -p udp --dport 8805 -s 10.0.0.10 -j ACCEPT
iptables -A INPUT -p udp --dport 8805 -j DROP

# Verify Open5GS version and apply upstream patch
git -C open5gs log --oneline | grep 028e1dbb5e3271035ccee906ef417a97fc523f71 \
    || git -C open5gs cherry-pick 028e1dbb5e3271035ccee906ef417a97fc523f71

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.