A vulnerability was found in Open5GS up to 2.7.7. It has been classified as problematic. The affected element is the function ogs_dbi_subscription_data in the library /lib/dbi/subscription.c of the component UDR. This manipulation of the argument supi_id causes denial of service.

This vulnerability appears as CVE-2026-7708. The attack may be initiated remotely. In addition, an exploit is available.

The project was informed of the problem early through an issue report but has not responded yet.