CVE-2025-15686
A vulnerability has been found in Open5GS up to 2.7.6. Affected by this issue is the function fd_msg_sess_get of the component HSS Service.
CVSS
4.3
Medio
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 12 ago 2026 · Última mod.: 12 ago 2026 · CWE-404
Sin historial EPSS suficiente todavía.
A vulnerability has been found in Open5GS up to 2.7.6. Affected by this issue is the function fd_msg_sess_get of the component HSS Service. Such manipulation of the argument Session-Id leads to denial of service. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project locked and limited conversation to collaborators.
- github.comhttps://github.com/open5gs/open5gs/
- github.comhttps://github.com/open5gs/open5gs/issues/4190
- github.comhttps://github.com/user-attachments/files/23847497/HSS_ULR_error_poc.pcapng.zip
- vuldb.comhttps://vuldb.com/cve/CVE-2025-15686
- vuldb.comhttps://vuldb.com/submit/867104
- vuldb.comhttps://vuldb.com/vuln/387279
- vuldb.comhttps://vuldb.com/vuln/387279/cti
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2025-156874.3 MED—
——0A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb of the component SMF Diameter Gx Credit-Control-Answer Handler. The manipulation results in denial of service. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.7.7 is recommended to address this issue. The patch is identified as f23d7a5e959acd8f37b925dc29b85f26b7d391cb. Upgrading the affected component is advised.5hCVE-2026-193822.3 BAJ2.0%
——1A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan.sys of the component MSR Index Handler. Executing a manipulation can lead to memory leak. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.5hCVE-2026-193625.3 MED30.1%
——9A vulnerability has been found in lmammino oidc-authorizer 0.4.0. This issue affects the function parse_token_from_header of the file src/parse_token_from_header.rs of the component Authorization Header Parsing. The manipulation of the argument authorization_token leads to denial of service. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.5hCVE-2026-175015.3 MED34.6%
——10A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-to-GBNF Conversion. This manipulation causes uncontrolled recursion. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.15dCVE-2026-175005.3 MED34.6%
——10A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. The manipulation results in null pointer dereference. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.16dCVE-2026-387635.5 MED7.3%
——2An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_1382819d