All 37 CVE vulnerabilities found in free5gc, with AI-generated Chinese analysis, references, and POCs.
This page details vulnerability data associated with Free5GC, an open-source implementation of the 5G core network, categorized under common weakness types and industry tags. The collected data encompasses a wide range of security flaws, including buffer overflows, authentication bypasses, and insecure configurations, covering incidents reported from the initial public release of the project through the present day. Users can leverage this resource to track vendor advisories and security patches issued by the Free5GC community, gain a deeper understanding of the specific weakness classes that affect 5G core infrastructure, and examine the historical trend of vulnerabilities within this specific product ecosystem. By aggregating these data points, the page serves as a central reference for security researchers and network operators to assess the risk posture of their deployments. It highlights recurring issues that may impact the integrity, confidentiality, and availability of 5G services. The information is structured to facilitate comprehensive analysis, allowing stakeholders to identify patterns in defect introduction and remediation speeds. This historical view aids in making informed decisions regarding upgrades, mitigation strategies, and third-party component audits. Whether you are conducting a security audit or monitoring threat landscapes, this compilation provides essential context on the evolution of security issues within the Free5GC software suite, ensuring that potential risks are recognized and addressed proactively.
Vendor: n/a
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-33064 | free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereference CWE-478 | 7.5 | - | 2026-03-20 |
| CVE-2026-33191 | free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error CWE-158 | 7.5 | - | 2026-03-20 |
| CVE-2026-2525 | Free5GC PFCP UDP Endpoint denial of service CWE-404 | 5.3 | Medium | 2026-02-16 |
| CVE-2026-1976 | Free5GC SMF SessionDeletionResponse null pointer dereference CWE-476 | 5.3 | Medium | 2026-02-06 |
| CVE-2026-1975 | Free5GC pfcp_reports.go identityTriggerType null pointer dereference CWE-476 | 5.3 | Medium | 2026-02-06 |
| CVE-2026-1974 | Free5GC SMF datapath.go ResolveNodeIdToIp denial of service CWE-404 | 5.3 | Medium | 2026-02-06 |
| CVE-2026-1973 | Free5GC SMF establishPfcpSession null pointer dereference CWE-476 | 5.3 | Medium | 2026-02-06 |
All 37 known CVE vulnerabilities affecting free5gc with full Chinese analysis, references, and POCs where available.