CVE-2026-33063
- EPSS 0.65%
- Veröffentlicht 20.03.2026 03:16:01
- Zuletzt bearbeitet 27.03.2026 17:06:55
free5GC is an open source 5G core network. free5GC AUSF prior to version 1.4.2 has is an Improper Null Check vulnerability leading to Denial of Service. All deployments of free5GC v4.0.1 using the AUSF UE authentication service (`/nausf-auth/v1/ue-au...
CVE-2026-33062
- EPSS 0.67%
- Veröffentlicht 20.03.2026 03:16:01
- Zuletzt bearbeitet 27.03.2026 17:13:12
free5GC is an open source 5G core network. free5GC NRF prior to version 1.4.2 has an Improper Input Validation vulnerability leading to Denial of Service. All deployments of free5GC using the NRF discovery service are affected. The `EncodeGroupId` fu...
CVE-2026-32937
- EPSS 0.4%
- Veröffentlicht 20.03.2026 03:16:00
- Zuletzt bearbeitet 27.03.2026 17:21:06
free5GC is an open source 5G core network. free5GC CHF prior to version 1.2.2 has an out-of-bounds slice access vulnerability in the CHF `nchf-convergedcharging` service. A valid authenticated request to PUT `/nchf-convergedcharging/v3/recharging/:ue...
CVE-2026-2525
- EPSS 0.49%
- Veröffentlicht 16.02.2026 01:02:06
- Zuletzt bearbeitet 19.02.2026 19:48:12
A vulnerability has been found in Free5GC up to 4.1.0. This affects an unknown function of the component PFCP UDP Endpoint. Such manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the publi...
CVE-2025-70123
- EPSS 0.33%
- Veröffentlicht 13.02.2026 00:00:00
- Zuletzt bearbeitet 18.02.2026 15:40:29
An improper input validation and protocol compliance vulnerability in free5GC v4.0.1 allows remote attackers to cause a denial of service. The UPF incorrectly accepts a malformed PFCP Association Setup Request, violating 3GPP TS 29.244. This places t...
CVE-2025-70122
- EPSS 0.34%
- Veröffentlicht 13.02.2026 00:00:00
- Zuletzt bearbeitet 18.02.2026 15:40:09
A heap buffer overflow vulnerability in the UPF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted PFCP Session Modification Request. The issue occurs in the SDFFilterFields.UnmarshalBinary function (sdf-fi...
CVE-2025-70121
- EPSS 0.34%
- Veröffentlicht 13.02.2026 00:00:00
- Zuletzt bearbeitet 18.02.2026 15:45:58
An array index out of bounds vulnerability in the AMF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted 5GS Mobile Identity in a NAS Registration Request message. The issue occurs in the GetSUCI method (NA...
CVE-2026-1975
- EPSS 0.53%
- Veröffentlicht 06.02.2026 03:15:49
- Zuletzt bearbeitet 09.02.2026 15:15:28
A security flaw has been discovered in Free5GC up to 4.1.0. This impacts the function identityTriggerType of the file pfcp_reports.go. The manipulation results in null pointer dereference. The attack can be executed remotely. The exploit has been rel...
CVE-2026-1976
- EPSS 0.53%
- Veröffentlicht 06.02.2026 03:15:49
- Zuletzt bearbeitet 09.02.2026 15:04:08
A weakness has been identified in Free5GC up to 4.1.0. Affected is the function SessionDeletionResponse of the component SMF. This manipulation causes null pointer dereference. The attack is possible to be carried out remotely. The exploit has been m...
CVE-2026-1974
- EPSS 0.5%
- Veröffentlicht 06.02.2026 02:16:05
- Zuletzt bearbeitet 09.02.2026 15:47:30
A vulnerability was identified in Free5GC up to 4.1.0. This affects the function ResolveNodeIdToIp of the file internal/sbi/processor/datapath.go of the component SMF. The manipulation leads to denial of service. Remote exploitation of the attack is ...