CVE-2026-30653
- EPSS 0.39%
- Veröffentlicht 24.03.2026 00:00:00
- Zuletzt bearbeitet 24.03.2026 20:16:26
An issue in Free5GC v.4.2.0 and before allows a remote attacker to cause a denial of service via the function HandleAuthenticationFailure of the component AMF
CVE-2026-4531
- EPSS 0.43%
- Veröffentlicht 22.03.2026 01:32:11
- Zuletzt bearbeitet 24.04.2026 16:32:53
A weakness has been identified in Free5GC 4.1.0. Affected is the function HandleRegistrationComplete of the file internal/gmm/handler.go of the component AMF. Executing a manipulation can lead to denial of service. The attack may be performed from re...
CVE-2026-33191
- EPSS 0.35%
- Veröffentlicht 20.03.2026 08:16:12
- Zuletzt bearbeitet 23.03.2026 18:24:15
Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions prior to 1.4.2 are vulnerable to null byte injection in URL path parameters. A remote attacker can inject null bytes (URL-encoded as %00) into t...
CVE-2026-33065
- EPSS 0.28%
- Veröffentlicht 20.03.2026 08:16:12
- Zuletzt bearbeitet 23.03.2026 18:32:57
Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. In versions prior to 1.4.2, the UDM incorrectly converts a downstream 400 Bad Request (from UDR) into a 500 Internal Server Error when handling DELETE re...
CVE-2026-33064
- EPSS 0.49%
- Veröffentlicht 20.03.2026 08:16:12
- Zuletzt bearbeitet 23.03.2026 18:43:25
Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions prior to 1.4.2 are vulnerable to procedure panic caused by Nil Pointer Dereference in the /sdm-subscriptions endpoint. A remote attacker can cau...
CVE-2026-33192
- EPSS 0.32%
- Veröffentlicht 20.03.2026 08:09:07
- Zuletzt bearbeitet 23.03.2026 18:32:46
Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. In versions prior to 1.4.2, the UDM incorrectly converts a downstream 400 Bad Request (from UDR) into a 500 Internal Server Error when handling PATCH req...
CVE-2026-33063
- EPSS 0.65%
- Veröffentlicht 20.03.2026 03:16:01
- Zuletzt bearbeitet 27.03.2026 17:06:55
free5GC is an open source 5G core network. free5GC AUSF prior to version 1.4.2 has is an Improper Null Check vulnerability leading to Denial of Service. All deployments of free5GC v4.0.1 using the AUSF UE authentication service (`/nausf-auth/v1/ue-au...
CVE-2026-33062
- EPSS 0.67%
- Veröffentlicht 20.03.2026 03:16:01
- Zuletzt bearbeitet 27.03.2026 17:13:12
free5GC is an open source 5G core network. free5GC NRF prior to version 1.4.2 has an Improper Input Validation vulnerability leading to Denial of Service. All deployments of free5GC using the NRF discovery service are affected. The `EncodeGroupId` fu...
CVE-2026-32937
- EPSS 0.4%
- Veröffentlicht 20.03.2026 03:16:00
- Zuletzt bearbeitet 27.03.2026 17:21:06
free5GC is an open source 5G core network. free5GC CHF prior to version 1.2.2 has an out-of-bounds slice access vulnerability in the CHF `nchf-convergedcharging` service. A valid authenticated request to PUT `/nchf-convergedcharging/v3/recharging/:ue...
CVE-2026-2525
- EPSS 0.49%
- Veröffentlicht 16.02.2026 01:02:06
- Zuletzt bearbeitet 19.02.2026 19:48:12
A vulnerability has been found in Free5GC up to 4.1.0. This affects an unknown function of the component PFCP UDP Endpoint. Such manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the publi...