CVE-2026-1682
- EPSS 0.06%
- Veröffentlicht 30.01.2026 14:16:07
- Zuletzt bearbeitet 23.02.2026 10:16:18
A flaw has been found in Free5GC SMF up to 4.1.0. Affected is the function HandlePfcpAssociationReleaseRequest of the file internal/pfcp/handler/handler.go of the component PFCP UDP Endpoint. Executing a manipulation can lead to null pointer derefere...
CVE-2025-66719
- EPSS 0.04%
- Veröffentlicht 23.01.2026 00:00:00
- Zuletzt bearbeitet 11.02.2026 19:55:25
An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck() function in file internal/sbi/processor/access_token.go bypasses all scope validation when the attacker uses a crafted targetNF...
CVE-2025-65562
- EPSS 0.5%
- Veröffentlicht 18.12.2025 00:00:00
- Zuletzt bearbeitet 07.01.2026 21:01:21
The free5GC UPF suffers from a lack of bounds checking on the SEID when processing PFCP Session Deletion Requests. An unauthenticated remote attacker can send a request with a very large SEID (e.g., 0xFFFFFFFFFFFFFFFF) that causes an integer conversi...
CVE-2025-65561
- EPSS 0.08%
- Veröffentlicht 18.12.2025 00:00:00
- Zuletzt bearbeitet 07.01.2026 21:00:58
An issue was discovered in function LocalNode.Sess in free5GC 4.1.0 allowing attackers to cause a denial of service or other unspecified impacts via crafted header Local SEID to the PFCP Session Modification Request.
CVE-2025-60638
- EPSS 0.07%
- Veröffentlicht 24.11.2025 00:00:00
- Zuletzt bearbeitet 01.12.2025 16:14:56
An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Nnssf_NSSAIAvailability API.
CVE-2025-60633
- EPSS 0.07%
- Veröffentlicht 24.11.2025 00:00:00
- Zuletzt bearbeitet 01.12.2025 16:16:12
An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via the Nudm_SubscriberDataManagement API.
CVE-2025-60632
- EPSS 0.04%
- Veröffentlicht 24.11.2025 00:00:00
- Zuletzt bearbeitet 01.12.2025 16:16:31
An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Npcf_BDTPolicyControl API.
CVE-2025-63679
- EPSS 0.08%
- Veröffentlicht 12.11.2025 19:15:37
- Zuletzt bearbeitet 31.12.2025 16:12:47
free5gc v4.1.0 and before is vulnerable to Buffer Overflow. When AMF receives an UplinkRANConfigurationTransfer NGAP message from a gNB, the AMF process crashes.
CVE-2025-56394
- EPSS 0.08%
- Veröffentlicht 23.09.2025 18:15:35
- Zuletzt bearbeitet 08.10.2025 17:56:44
Free5gc 4.0.1 is vulnerable to Buffer Overflow. The AMF incorrectly validates the 5GS mobile identity, resulting in slice reference overflow.
CVE-2025-29632
- EPSS 0.09%
- Veröffentlicht 29.05.2025 00:00:00
- Zuletzt bearbeitet 25.06.2025 15:43:17
Buffer Overflow vulnerability in Free5gc v.4.0.0 allows a remote attacker to cause a denial of service via the AMF, NGAP, security.go, handler_generated.go, handleInitialUEMessageMain, DecodePlainNasNoIntegrityCheck, GetSecurityHeaderType components