CVE-2026-42081
- EPSS 0.27%
- Veröffentlicht 27.05.2026 15:59:58
- Zuletzt bearbeitet 29.05.2026 19:24:54
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against its locally stored values, as mandated by 3GPP TS 33....
CVE-2026-42082
- EPSS 0.25%
- Veröffentlicht 27.05.2026 15:59:21
- Zuletzt bearbeitet 28.05.2026 19:22:15
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not enforce the concurrent security procedure rules defined in 3GPP TS 33.501 §6.9.5.1. The AMF does not check for ongoing N2 handover procedures...
CVE-2026-42083
- EPSS 0.32%
- Veröffentlicht 27.05.2026 15:56:11
- Zuletzt bearbeitet 28.05.2026 18:40:59
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers and disclosure of subscriber SUPI. In NewServer(), the smP...
CVE-2026-42459
- EPSS 0.32%
- Veröffentlicht 27.05.2026 15:53:45
- Zuletzt bearbeitet 28.05.2026 18:35:51
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the free5GC UDM component fails to validate the supi path parameter in six GET handlers of the nudm-sdm (Subscriber Data Management) service. An unauthenticated attacker...
CVE-2026-44315
- EPSS 0.31%
- Veröffentlicht 27.05.2026 15:52:51
- Zuletzt bearbeitet 28.05.2026 18:34:15
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-pfd-management API without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can create, read, and...
CVE-2026-44316
- EPSS 0.4%
- Veröffentlicht 27.05.2026 15:52:07
- Zuletzt bearbeitet 28.05.2026 18:31:42
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's PCF POST /npcf-smpolicycontrol/v1/sm-policies handler (HandleCreateSmPolicyRequest) panics with a nil-pointer dereference when a downstream OpenAPI consumer ca...
CVE-2026-44317
- EPSS 0.35%
- Veröffentlicht 27.05.2026 15:50:18
- Zuletzt bearbeitet 28.05.2026 18:30:58
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's PCF POST /npcf-policyauthorization/v1/app-sessions handler panics on a single authenticated request whose ascReqData.suppFeat == "1" (enabling traffic-routing ...
CVE-2026-44319
- EPSS 0.4%
- Veröffentlicht 27.05.2026 15:49:20
- Zuletzt bearbeitet 28.05.2026 17:50:05
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF terminates the entire process when a stored PFD-subscription notifyUri cannot be reached. In PfdChangeNotifier.FlushNotifications(), the notifier calls Nne...
CVE-2026-44320
- EPSS 0.24%
- Veröffentlicht 27.05.2026 15:48:22
- Zuletzt bearbeitet 28.05.2026 18:23:47
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-callback route group without inbound OAuth2/bearer-token authorization. A forged or arbitrary bearer token (e.g. Authorization: Bearer not-...
CVE-2026-44321
- EPSS 0.36%
- Veröffentlicht 27.05.2026 15:47:33
- Zuletzt bearbeitet 28.05.2026 18:01:21
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound OAuth2 middleware. The POST /upi/v1/upNodesLinks create-or-update handler accepts attacker-controlled...