Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

free5gc — Vulnerabilities & Security Advisories 38

All 38 CVE vulnerabilities found in free5gc, with AI-generated Chinese analysis, references, and POCs.

This page documents security weaknesses affecting Free5GC, an open-source 5G core network implementation managed by the Linux Foundation. It aggregates a comprehensive collection of known vulnerabilities related to this specific software product, covering the period from its initial release through recent updates. By consolidating data from multiple sources, the page aims to provide a unified view of the security posture for this critical telecommunications infrastructure component. Users can track vendor advisories to stay informed about official patches and mitigation strategies issued by the Free5GC project. Furthermore, the aggregated data allows for a deeper understanding of specific weakness classes prevalent in open-source 5G core designs, helping analysts identify common patterns in code errors or configuration flaws. Researchers and security professionals can also look up the product's vulnerability history to assess how the software has evolved over time and how responsive the development team has been to reported issues. This resource serves as a factual reference point for evaluating the risk associated with deploying Free5GC in production environments. The content is strictly informational and derived from publicly available security databases and project announcements. It does not include speculative or unverified claims. The goal is to facilitate transparent analysis of the security landscape surrounding this widely adopted open-source solution.

Vendor: n/a

CVE IDTitleCVSSSeverityPublished
CVE-2026-53551 free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure CWE-20 6.9 Medium2026-07-31
CVE-2026-42081 free5GC: UE Security Capability bypass on NGAP PathSwitchRequest CWE-358 6.1 Medium2026-05-27
CVE-2026-42082 free5GC: Missing Concurrent NAS SMC Validation During NGAP Handover CWE-358 3.7 Low2026-05-27
CVE-2026-42083 free5GC: PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers and disclosure of subscriber SUPI CWE-862 8.2 High2026-05-27
CVE-2026-42459 free5GC: Improper Input Validation and Generation of Error Message Containing Sensitive Information in github.com/free5gc/udm CWE-20--2026-05-27
CVE-2026-44315 free5GC: NEF 3gpp-pfd-management API is unauthenticated; forged bearer tokens can create, read, and delete PFD transactions CWE-862 9.4 Critical2026-05-27
CVE-2026-44316 free5GC: PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference CWE-476 7.5 High2026-05-27
CVE-2026-44317 free5GC: PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference CWE-476 6.5 Medium2026-05-27
CVE-2026-44319 free5GC: NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-controlled notifyUri) CWE-20 7.5 High2026-05-27
CVE-2026-44320 free5GC: NEF nnef-callback route group is unauthenticated; forged callback requests are accepted into the processing path CWE-306 7.3 High2026-05-27
CVE-2026-44321 free5GC: SMF UPI POST /upi/v1/upNodesLinks exits the SMF process on overlapping UE pools (unauthenticated, reachable Fatalf) CWE-306 7.5 High2026-05-27
CVE-2026-44322 free5GC: NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR access failure due to nil ProblemDetails dereference CWE-476 7.5 High2026-05-27
CVE-2026-44323 free5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference) CWE-476 4.3 Medium2026-05-27
CVE-2026-44324 free5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request) CWE-704 6.5 Medium2026-05-27
CVE-2026-44325 free5GC: NRF POST /oauth2/token structured-form parser type-confusion panic family (Reflect.Set on incompatible types) CWE-20 7.5 High2026-05-27
CVE-2026-44326 free5GC: NEF 3gpp-traffic-influence API is unauthenticated; missing or forged bearer tokens can create, read, patch, and delete subscriptions CWE-862 9.4 Critical2026-05-27
CVE-2026-44327 free5GC: NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handler CWE-306 10.0 Critical2026-05-27
CVE-2026-44328 free5GC: SMF UPI DELETE /upi/v1/upNodesLinks/{ref} panics on AN-node deletion via nil UPF dereference; unauthenticated, state-mutating CWE-306 8.2 High2026-05-27
CVE-2026-44329 free5GC: SMF UPI management interface lacks auth middleware; unauthenticated topology read/write requests reach handlers CWE-306 10.0 Critical2026-05-27
CVE-2026-44330 free5GC: NEF nnef-pfdmanagement API is unauthenticated; forged bearer tokens can read PFD data and create/delete PFD subscriptions CWE-863 10.0 Critical2026-05-27
CVE-2026-44318 free5GC: BSF concurrent PUT /nbsf-management/v1/subscriptions/{subId} crashes the BSF process via concurrent map read/write on Subscriptions CWE-362 6.5 Medium2026-05-27
CVE-2026-40249 free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors CWE-754 9.1AICriticalAI2026-04-16
CVE-2026-40248 free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions CWE-285 7.5AIHighAI2026-04-16
CVE-2026-40247 free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions CWE-285 5.3AIMediumAI2026-04-16
CVE-2026-40246 free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions CWE-285 5.3AIMediumAI2026-04-16
CVE-2026-40245 Free5GC: UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication CWE-200 7.5 High2026-04-15
CVE-2026-5661 Free5GC NGSetupRequest denial of service CWE-404 5.3 Medium2026-04-06
CVE-2026-5360 Free5GC aper type confusion CWE-843 3.7 Low2026-04-02
CVE-2026-4531 Free5GC AMF handler.go HandleRegistrationComplete denial of service CWE-404 5.3 Medium2026-03-22
CVE-2026-33192 free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions reques CWE-209 3.7 -2026-03-20

All 38 known CVE vulnerabilities affecting free5gc with full Chinese analysis, references, and POCs where available.