Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-78156
n/a Open5GS — Open5GS S6a Authentication-Information-Request hss-s6a-path.c hss_ogs_diam_s6a_air_cb heap-based overflow
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N L N L L L 2.1 .0056 44.7 —
AFFECTED
Product Versions Fixed
Open5GS 2.8.0 – —
TIMELINE
Aug 23 Reserved by VulDB
Aug 23 Published (CNA: VulDB)
Aug 24 RESCORED — CVE-2026-78156 (Open5GS). CVSS 5.3 → 2.1 (NVD).
Description
A security vulnerability has been detected in Open5GS 2.8.0. Affected by this issue is the function hss_ogs_diam_s6a_air_cb of the file src/hss/hss-s6a-path.c of the component S6a Authentication-Information-Request Handler. Such manipulation of the argument Visited-PLMN-Id leads to heap-based buffer overflow. The attack may be performed from remote. The name of the patch is a9c82ee0b590d76a581b0580cb46b598984e2392. A patch should be applied to remediate this issue.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| August 23, 2026 | Reserved | Reserved by VulDB |
| August 23, 2026 | Published | Published (CNA: VulDB) |
| August 24, 2026 | RESCORED | RESCORED — CVE-2026-78156 (Open5GS). CVSS 5.3 → 2.1 (NVD). |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| n/a | Open5GS | — | 2.8.0 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-78156 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.