vciy

CVEs we hold for Free5gc

Records whose assigning authority named Free5gc as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-5661Free5GC NGSetupRequest denial of servicen/a Free5GC
CVE-2026-55785free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKAfree5gc
CVE-2026-55784free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPIfree5gc
CVE-2026-55068free5GC: NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service…free5gc
CVE-2026-5360Free5GC aper type confusionn/a Free5GC
CVE-2026-53551free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failurefree5gc; free5gc ausf
CVE-2026-47780free5GC: UDR Improper ueId validation in free5GC EE subscription handlers allows arbitrary identifier persistencefree5gc
CVE-2026-4531Free5GC AMF handler.go HandleRegistrationComplete denial of servicen/a Free5GC
CVE-2026-44330free5GC: NEF nnef-pfdmanagement API is unauthenticated; forged bearer tokens can read PFD data and create/delete PFD…free5gc
CVE-2026-44329free5GC: SMF UPI management interface lacks auth middleware; unauthenticated topology read/write requests reach handlersfree5gc
CVE-2026-44328free5GC: SMF UPI DELETE /upi/v1/upNodesLinks/{ref} panics on AN-node deletion via nil UPF dereference…free5gc
CVE-2026-44327free5GC: NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handlerfree5gc
CVE-2026-44326free5GC: NEF 3gpp-traffic-influence API is unauthenticated; missing or forged bearer tokens can create, read, patch…free5gc
CVE-2026-44325free5GC: NRF POST /oauth2/token structured-form parser type-confusion panic family (Reflect.Set on incompatible types)free5gc
CVE-2026-44324free5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single…free5gc
CVE-2026-44323free5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference)free5gc
CVE-2026-44322free5GC: NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR access failure due to nil ProblemDetails…free5gc
CVE-2026-44321free5GC: SMF UPI POST /upi/v1/upNodesLinks exits the SMF process on overlapping UE pools (unauthenticated, reachable…free5gc
CVE-2026-44320free5GC: NEF nnef-callback route group is unauthenticated; forged callback requests are accepted into the processing…free5gc
CVE-2026-44319free5GC: NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-controlled notifyUri)free5gc
CVE-2026-44318free5GC: BSF concurrent PUT /nbsf-management/v1/subscriptions/{subId} crashes the BSF process via concurrent map…free5gc
CVE-2026-44317free5GC: PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer…free5gc
CVE-2026-44316free5GC: PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereferencefree5gc
CVE-2026-44315free5GC: NEF 3gpp-pfd-management API is unauthenticated; forged bearer tokens can create, read, and delete PFD…free5gc
CVE-2026-42459free5GC: Improper Input Validation and Generation of Error Message Containing Sensitive Information in…free5gc
CVE-2026-42083free5GC: PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers…free5gc
CVE-2026-42082free5GC: Missing Concurrent NAS SMC Validation During NGAP Handoverfree5gc
CVE-2026-42081free5GC: UE Security Capability bypass on NGAP PathSwitchRequestfree5gc
CVE-2026-41136free5GC AMF missing default case in Content-Type switch in HTTPUEContextTransferfree5gc amf
CVE-2026-41135free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Servicefree5gc pcf
CVE-2026-40343free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creationfree5gc udr
CVE-2026-40249free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates…free5gc
CVE-2026-40248free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptionsfree5gc
CVE-2026-40247free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptionsfree5gc
CVE-2026-40246free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptionsfree5gc
CVE-2026-40245Free5GC: UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authenticationfree5gc
CVE-2026-33192free5GC UDM incorrectly returns 500 for empty supi path parameter in PATCH sdm-subscriptions requesfree5gc
CVE-2026-33191free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Errorfree5gc
CVE-2026-33065free5GC UDM incorrectly returns 500 for empty supi path parameter in DELETE sdm-subscriptions requestfree5gc
CVE-2026-33064free5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer Dereferencefree5gc
CVE-2026-33063free5GC AUSF UE Authentication Panic on Nil SuciSupiMap Interface Conversionfree5gc ausf
CVE-2026-33062free5GC NRF Discovery EncodeGroupId Function Panics on Malformed group-id-list Parameterfree5gc nrf
CVE-2026-32937free5GC CHF has Out-of-Bounds Slice Access that Leads to DoSfree5gc chf
CVE-2026-27643free5GC has improper error handling in NEF with information exposurefree5gc udr
CVE-2026-27642free5GC has Improper Input Validation in UDM UEAU Servicefree5gc udm
CVE-2026-26025free5GC SMF crash (nil pointer dereference) on PFCP SessionReportRequest when ReportType.USAR=1 and UsageReport omits…free5gc smf
CVE-2026-26024free5GC SMF crash (nil pointer dereference) on PFCP SessionReportRequest when ReportType.USAR=1 and UsageReport omits…free5gc smf
CVE-2026-25501free5GC SMF crash (nil pointer dereference) on PFCP SessionReportRequest when ReportType.DLDR is set but…free5gc smf
CVE-2026-2525Free5GC PFCP UDP Endpoint denial of servicen/a Free5GC
CVE-2026-1976Free5GC SMF SessionDeletionResponse null pointer dereferencen/a Free5GC
CVE-2026-1975Free5GC pfcp_reports.go identityTriggerType null pointer dereferencen/a Free5GC
CVE-2026-1974Free5GC SMF datapath.go ResolveNodeIdToIp denial of servicen/a Free5GC
CVE-2026-1973Free5GC SMF establishPfcpSession null pointer dereferencen/a Free5GC
CVE-2026-1739Free5GC pcf smpolicy.go HandleCreateSmPolicyRequest null pointer dereferenceFree5GC pcf
CVE-2026-1684Free5GC SMF PFCP UDP Endpoint pfcp_reports.go HandleReports denial of serviceFree5GC SMF
CVE-2026-1683Free5GC SMF PFCP handler.go HandlePfcpSessionReportRequest denial of serviceFree5GC SMF
CVE-2026-1682Free5GC SMF PFCP UDP Endpoint handler.go HandlePfcpAssociationReleaseRequest null pointer dereferenceFree5GC SMF
CVE-2025-69253free5GC vulnerable to improper error handling in NEF with information exposurefree5gc udr
CVE-2025-69252free5GC has Null Pointer Dereference in UDM, Leading to Service Panicfree5gc udm
CVE-2025-69251free5GC has Improper Input Validation in UDM, Leading to Information Exposurefree5gc udm
CVE-2025-69250free5GC has Improper Error Handling in UDM, Leading to Information Exposurefree5gc udm
CVE-2025-69248free5GC has Array Index Out of Bounds in AMF Leading to Denial of Servicefree5gc amf
CVE-2025-69247free5GC has Heap Buffer Overflow in UPF Leading to Denial of Servicefree5gc go-upf
CVE-2025-69232free5GC hasProtocol Compliance Violation in UPF Leading to SMF Service Disruptionfree5gc smf
CVE-2025-69208free5GC UDR's NEF incorrectly returns 500 for missing PFD data (UDR 404) in Nnef_PfdManagement GET requestfree5gc udr
CVE-2023-4659Cross-Site Request Forgery in Free5GcFree5Gc Open5Gc

66 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.