CVE-2026-94043
- EPSS 0.34%
- Veröffentlicht 20.09.2026 18:00:10
- Zuletzt bearbeitet 21.09.2026 20:17:40
A vulnerability was determined in Free5GC up to 4.2.3. This vulnerability affects unknown code of the file /corefuzzer_deps/free5gc/NFs/amf/internal/gmm/handler.go of the component Gmm Handler. This manipulation causes race condition. The attack can ...
CVE-2026-47780
- EPSS -
- Veröffentlicht 15.09.2026 14:43:49
- Zuletzt bearbeitet 30.09.2026 17:51:56
free5GC is an open-source implementation of the 5G core network. In 4.2.3 and earlier, HandleCreateEeSubscriptions and HandleQueryeesubscriptions in free5gc/udr internal/sbi/api_datarepository.go validate the ueId path value with a regular expression...
CVE-2026-75439
- EPSS 0.25%
- Veröffentlicht 04.09.2026 00:00:00
- Zuletzt bearbeitet 14.09.2026 14:17:09
An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of service via the UPF component
CVE-2026-55785
- EPSS 0.28%
- Veröffentlicht 28.08.2026 22:25:06
- Zuletzt bearbeitet 08.09.2026 21:11:31
free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the AUSF component performs cryptographic authentication comparisons in internal/sbi/processor/ue_authentication.go with ordinary equality helpers. Auth5gAkaComfirmReque...
CVE-2026-55784
- EPSS 0.25%
- Veröffentlicht 28.08.2026 22:23:41
- Zuletzt bearbeitet 08.09.2026 21:11:31
free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores per-subscriber authentication state in a global sync.Map named AUSFContext.UePool in internal/context/context.go, keyed only by S...
CVE-2026-55068
- EPSS 0.44%
- Veröffentlicht 28.08.2026 16:57:12
- Zuletzt bearbeitet 08.09.2026 21:11:31
free5GC is an open-source implementation of the 5G core network. In 4.2.2 and earlier, the NRF RegisterNFInstance handler at PUT /nnrf-nfm/v1/nf-instances/{nfInstanceID} accepts NF Profiles without enforcing UUID format, nfStatus enum values, heartBe...
CVE-2026-30050
- EPSS 0.32%
- Veröffentlicht 27.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 20:12:02
An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PATCH request.
CVE-2026-30051
- EPSS 0.15%
- Veröffentlicht 27.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 20:59:32
An issue in the CreateUEContextProcedure function (/v1/ue-contexts/{supi}) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PUT request.
CVE-2026-30056
- EPSS 0.32%
- Veröffentlicht 27.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 20:12:02
A NULL pointer dereference in the AMF NGAP Dispatcher component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted NGAP messages during the initialization of a new RAN connection.
CVE-2026-30057
- EPSS 0.32%
- Veröffentlicht 27.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 20:12:02
An issue in the CreateUEContext handler component of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted request.