CVE-2026-1973
- EPSS 0.53%
- Veröffentlicht 06.02.2026 02:16:05
- Zuletzt bearbeitet 09.02.2026 15:48:21
A vulnerability was determined in Free5GC up to 4.1.0. The impacted element is the function establishPfcpSession of the component SMF. Executing a manipulation can lead to null pointer dereference. The attack may be launched remotely. The exploit has...
CVE-2026-1684
- EPSS 0.5%
- Veröffentlicht 30.01.2026 14:32:07
- Zuletzt bearbeitet 23.02.2026 10:16:18
A vulnerability was found in Free5GC SMF up to 4.1.0. Affected by this issue is the function HandleReports of the file /internal/context/pfcp_reports.go of the component PFCP UDP Endpoint. The manipulation results in denial of service. The attack can...
CVE-2026-1683
- EPSS 0.64%
- Veröffentlicht 30.01.2026 14:16:07
- Zuletzt bearbeitet 23.02.2026 10:16:18
A vulnerability has been found in Free5GC SMF up to 4.1.0. Affected by this vulnerability is the function HandlePfcpSessionReportRequest of the file internal/pfcp/handler/handler.go of the component PFCP. The manipulation leads to denial of service. ...
CVE-2026-1682
- EPSS 0.67%
- Veröffentlicht 30.01.2026 14:16:07
- Zuletzt bearbeitet 23.02.2026 10:16:18
A flaw has been found in Free5GC SMF up to 4.1.0. Affected is the function HandlePfcpAssociationReleaseRequest of the file internal/pfcp/handler/handler.go of the component PFCP UDP Endpoint. Executing a manipulation can lead to null pointer derefere...
CVE-2025-66719
- EPSS 0.31%
- Veröffentlicht 23.01.2026 00:00:00
- Zuletzt bearbeitet 11.02.2026 19:55:25
An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck() function in file internal/sbi/processor/access_token.go bypasses all scope validation when the attacker uses a crafted targetNF...
CVE-2025-65562
- EPSS 0.57%
- Veröffentlicht 18.12.2025 00:00:00
- Zuletzt bearbeitet 07.01.2026 21:01:21
The free5GC UPF suffers from a lack of bounds checking on the SEID when processing PFCP Session Deletion Requests. An unauthenticated remote attacker can send a request with a very large SEID (e.g., 0xFFFFFFFFFFFFFFFF) that causes an integer conversi...
CVE-2025-65561
- EPSS 0.43%
- Veröffentlicht 18.12.2025 00:00:00
- Zuletzt bearbeitet 07.01.2026 21:00:58
An issue was discovered in function LocalNode.Sess in free5GC 4.1.0 allowing attackers to cause a denial of service or other unspecified impacts via crafted header Local SEID to the PFCP Session Modification Request.
CVE-2025-60633
- EPSS 0.36%
- Veröffentlicht 24.11.2025 00:00:00
- Zuletzt bearbeitet 01.12.2025 16:16:12
An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via the Nudm_SubscriberDataManagement API.
CVE-2025-60632
- EPSS 0.24%
- Veröffentlicht 24.11.2025 00:00:00
- Zuletzt bearbeitet 01.12.2025 16:16:31
An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Npcf_BDTPolicyControl API.
CVE-2025-60638
- EPSS 0.35%
- Veröffentlicht 24.11.2025 00:00:00
- Zuletzt bearbeitet 01.12.2025 16:14:56
An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Nnssf_NSSAIAvailability API.