VYPR
High severity7.5NVD Advisory· Published Feb 24, 2026· Updated Jun 17, 2026

CVE-2026-26025

CVE-2026-26025

Description

free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, SMF panics and terminates when processing a malformed PFCP SessionReportRequest on the PFCP (UDP/8805) interface. No known upstream fix is available, but some workarounds are available. ACL/firewall the PFCP interface so only trusted UPF IPs can reach SMF (reduce spoofing/abuse surface); drop/inspect malformed PFCP SessionReportRequest messages at the network edge where feasible, and/or add recover() around PFCP handler dispatch to avoid whole-process termination (mitigation only).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Free5gc/SMF3 versions
    cpe:2.3:a:free5gc:smf:*:*:*:*:*:go:*:*+ 2 more
    • cpe:2.3:a:free5gc:smf:*:*:*:*:*:go:*:*range: <=1.4.1
    • (no CPE)range: <=1.4.1
    • (no CPE)range: <= 1.4.1
  • Free5gc/Free5gcllm-fuzzy
    Range: <=1.4.1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.