Opennetworking develops software infrastructure for telecommunications and software-defined networking environments, with a focused product line centered on ONOS (Open Networking Operating System), its controller platform, and related libraries such as libfluid_msg and User Plane Function components. The vendor's vulnerabilities concentrate in a modestly represented but prominent footprint and recur through weakness classes reflecting parsing and resource-management complexity inherent to network-control software: out-of-bounds reads, NULL pointer dereferences, unchecked return values leading to NULL-pointer conditions, incorrect control-flow logic, and uncontrolled resource consumption. A meaningful share of disclosed vulnerabilities reach serious severity levels, reflecting the criticality of control-plane and management-interface code in carrier networks. Defenders operating SDN infrastructure or telecommunications deployments built around ONOS should inventory affected versions and prioritize updates to network-control components; live exploitation, KEV status, and detailed severity breakdowns are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opennetworking over time
Signals from CVEs in this vendor scope (63 CVEs).
63 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29606CRITICAL An issue was discovered in ONOS 2.5.1. An intent with a large port number shows the CORRUPT state, which is misleading to a network operator. Improper handling of such port numbers | Apr 20, 2023 | 9.8 | 31 | NO | NO |
CVE-2018-1000155CRITICAL OpenFlow version 1.0 onwards contains a Denial of Service and Improper authorization vulnerability in OpenFlow handshake: The DPID (DataPath IDentifier) in the features_reply messa | May 24, 2018 | 9.8 | 31 | NO | NO |
CVE-2022-29604CRITICAL An issue was discovered in ONOS 2.5.1. An intent with an uppercase letter in a device ID shows the CORRUPT state, which is misleading to a network operator. Improper handling of ca | Apr 20, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-41591CRITICAL An issue in Open Network Foundation ONOS v2.7.0 allows attackers to create fake IP/MAC addresses and potentially execute a man-in-the-middle attack on communications between fake a | May 29, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-65568HIGH A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association, a PFCP Session Establishment | Dec 18, 2025 | 7.5 | 27 | NO | NO |
CVE-2025-65567HIGH A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association, a specially crafted PFCP Sess | Dec 18, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-65565HIGH A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.3-dev. After PFCP association is established, a PFCP Session | Dec 18, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-65564HIGH A denial-of-service vulnerability exists in the omec-upf (upf-epc-pfcpiface) in version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Association Setup Request that is | Dec 18, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-65563HIGH A denial-of-service vulnerability exists in the omec-project UPF (component upf-epc/pfcpiface) up to at least version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Asso | Dec 18, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-29310CRITICAL An issue in onos v2.7.0 allows attackers to trigger a packet deserialization problem when supplying a crafted LLDP packet. This vulnerability allows attackers to execute arbitrary | Mar 24, 2025 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (63 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opennetworking.
Media articles that mention a CVE ID that affects a product developed by Opennetworking — matched by CVE ID, not by vendor name.