A heap-based buffer overflow vulnerability has been identified in Open5GS version 2.8.0, specifically in the function hss_ogs_diam_s6a_air_cb located in src/hss/hss-s6a-path.c. The vulnerability is triggered by manipulating the Visited-PLMN-Id argument within the S6a Authentication-Information-Request Handler component. Remote exploitation is possible, making this a significant security risk for 5G core network deployments using Open5GS. A patch has been identified with commit hash a9c82ee0b590d76a581b0580cb46b598984e2392 on the Open5GS GitHub repository. Administrators are advised to apply the patch immediately to remediate the issue. The vulnerability has been tracked under CVE-2026-78156 and documented on both NVD and VulDB. No workaround is mentioned; patching is the recommended remediation path.