Free5gc
by Free5gc
Source repositories
CVEs (104)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-33191 | Hig | 0.49 | 8.6 | 0.00 | Mar 20, 2026 | Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions prior to 1.4.2 are vulnerable to null byte injection in URL path parameters. A remote attacker can inject null bytes (URL-encoded as %00) into the supi path parameter of the… | ||
| CVE-2026-26025 | Hig | 0.49 | 7.5 | 0.00 | Feb 24, 2026 | free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, SMF panics and terminates when processing a malformed PFCP SessionReportRequest on the PFCP (UDP/8805)… | ||
| CVE-2026-26024 | Hig | 0.49 | 7.5 | 0.00 | Feb 24, 2026 | free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, SMF panics and terminates when processing a malformed PFCP SessionReportRequest on the PFCP (UDP/8805)… | ||
| CVE-2026-25501 | Hig | 0.49 | 7.5 | 0.00 | Feb 24, 2026 | free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, SMF panics due to nil pointer dereference and the SMF process terminates. This is triggered by a malformed… | ||
| CVE-2025-69232 | Hig | 0.49 | 7.5 | 0.00 | Feb 23, 2026 | free5GC is an open-source project for 5th generation (5G) mobile core networks. free5GC go-upf versions up to and including 1.2.6, corresponding to free5gc smf up to and including 1.4.0, have an Improper Input Validation and Protocol Compliance vulnerability leading to Denial of… | ||
| CVE-2025-70123 | Hig | 0.49 | 7.5 | 0.00 | Feb 13, 2026 | An improper input validation and protocol compliance vulnerability in free5GC v4.0.1 allows remote attackers to cause a denial of service. The UPF incorrectly accepts a malformed PFCP Association Setup Request, violating 3GPP TS 29.244. This places the UPF in an inconsistent… | ||
| CVE-2025-70122 | Hig | 0.49 | 7.5 | 0.00 | Feb 13, 2026 | A heap buffer overflow vulnerability in the UPF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted PFCP Session Modification Request. The issue occurs in the SDFFilterFields.UnmarshalBinary function (sdf-filter.go) when processing a… | ||
| CVE-2025-70121 | Hig | 0.49 | 7.5 | 0.00 | Feb 13, 2026 | An array index out of bounds vulnerability in the AMF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted 5GS Mobile Identity in a NAS Registration Request message. The issue occurs in the GetSUCI method (NAS_MobileIdentity5GS.go) when… | ||
| CVE-2025-65562 | Hig | 0.49 | 7.5 | 0.01 | Dec 18, 2025 | The free5GC UPF suffers from a lack of bounds checking on the SEID when processing PFCP Session Deletion Requests. An unauthenticated remote attacker can send a request with a very large SEID (e.g., 0xFFFFFFFFFFFFFFFF) that causes an integer conversion/underflow in… | ||
| CVE-2025-63679 | Hig | 0.49 | 7.5 | 0.00 | Nov 12, 2025 | free5gc v4.1.0 and before is vulnerable to Buffer Overflow. When AMF receives an UplinkRANConfigurationTransfer NGAP message from a gNB, the AMF process crashes. | ||
| CVE-2025-56394 | Hig | 0.49 | 7.5 | 0.00 | Sep 23, 2025 | Free5gc 4.0.1 is vulnerable to Buffer Overflow. The AMF incorrectly validates the 5GS mobile identity, resulting in slice reference overflow. | ||
| CVE-2023-47347 | Hig | 0.49 | 7.5 | 0.01 | Nov 15, 2023 | Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP messages whose Sequence Number is mutated to overflow bytes. | ||
| CVE-2023-47345 | Hig | 0.49 | 7.5 | 0.01 | Nov 15, 2023 | Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP message with malformed PFCP Heartbeat message whose Recovery Time Stamp IE length is mutated to zero. | ||
| CVE-2023-47346 | Hig | 0.49 | 7.5 | 0.01 | Nov 13, 2023 | Buffer Overflow vulnerability in free5gc 3.3.0, UPF 1.2.0, and SMF 1.2.0 allows attackers to cause a denial of service via crafted PFCP messages. | ||
| CVE-2022-38871 | Hig | 0.49 | 7.5 | 0.01 | Nov 18, 2022 | In Free5gc v3.0.5, the AMF breaks due to malformed NAS messages. | ||
| CVE-2022-38870 | Hig | 0.49 | 7.5 | 0.03 | Oct 25, 2022 | Free5gc v3.2.1 is vulnerable to Information disclosure. | ||
| CVE-2026-44328 | Hig | 0.46 | 8.2 | 0.00 | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound OAuth2 middleware. On top of that, the DELETE /upi/v1/upNodesLinks/{upNodeRef} handler unconditionally dereferences upNode.UPF… | ||
| CVE-2026-42083 | Hig | 0.46 | 8.2 | 0.00 | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers and disclosure of subscriber SUPI. In NewServer(), the smPolicyGroup route group is… | ||
| CVE-2026-47780 | Med | 0.45 | — | 0.00 | Sep 15, 2026 | free5GC is an open-source implementation of the 5G core network. In 4.2.3 and earlier, HandleCreateEeSubscriptions and HandleQueryeesubscriptions in free5gc/udr internal/sbi/api_datarepository.go validate the ueId path value with a regular expression whose final .+ alternative… | ||
| CVE-2026-75439 | Hig | 0.42 | 7.5 | 0.00 | Sep 4, 2026 | An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of service via the UPF component |
- risk 0.49cvss 8.6epss 0.00
Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions prior to 1.4.2 are vulnerable to null byte injection in URL path parameters. A remote attacker can inject null bytes (URL-encoded as %00) into the supi path parameter of the…
- risk 0.49cvss 7.5epss 0.00
free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, SMF panics and terminates when processing a malformed PFCP SessionReportRequest on the PFCP (UDP/8805)…
- risk 0.49cvss 7.5epss 0.00
free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, SMF panics and terminates when processing a malformed PFCP SessionReportRequest on the PFCP (UDP/8805)…
- risk 0.49cvss 7.5epss 0.00
free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, SMF panics due to nil pointer dereference and the SMF process terminates. This is triggered by a malformed…
- risk 0.49cvss 7.5epss 0.00
free5GC is an open-source project for 5th generation (5G) mobile core networks. free5GC go-upf versions up to and including 1.2.6, corresponding to free5gc smf up to and including 1.4.0, have an Improper Input Validation and Protocol Compliance vulnerability leading to Denial of…
- risk 0.49cvss 7.5epss 0.00
An improper input validation and protocol compliance vulnerability in free5GC v4.0.1 allows remote attackers to cause a denial of service. The UPF incorrectly accepts a malformed PFCP Association Setup Request, violating 3GPP TS 29.244. This places the UPF in an inconsistent…
- risk 0.49cvss 7.5epss 0.00
A heap buffer overflow vulnerability in the UPF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted PFCP Session Modification Request. The issue occurs in the SDFFilterFields.UnmarshalBinary function (sdf-filter.go) when processing a…
- risk 0.49cvss 7.5epss 0.00
An array index out of bounds vulnerability in the AMF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted 5GS Mobile Identity in a NAS Registration Request message. The issue occurs in the GetSUCI method (NAS_MobileIdentity5GS.go) when…
- risk 0.49cvss 7.5epss 0.01
The free5GC UPF suffers from a lack of bounds checking on the SEID when processing PFCP Session Deletion Requests. An unauthenticated remote attacker can send a request with a very large SEID (e.g., 0xFFFFFFFFFFFFFFFF) that causes an integer conversion/underflow in…
- risk 0.49cvss 7.5epss 0.00
free5gc v4.1.0 and before is vulnerable to Buffer Overflow. When AMF receives an UplinkRANConfigurationTransfer NGAP message from a gNB, the AMF process crashes.
- risk 0.49cvss 7.5epss 0.00
Free5gc 4.0.1 is vulnerable to Buffer Overflow. The AMF incorrectly validates the 5GS mobile identity, resulting in slice reference overflow.
- risk 0.49cvss 7.5epss 0.01
Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP messages whose Sequence Number is mutated to overflow bytes.
- risk 0.49cvss 7.5epss 0.01
Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP message with malformed PFCP Heartbeat message whose Recovery Time Stamp IE length is mutated to zero.
- risk 0.49cvss 7.5epss 0.01
Buffer Overflow vulnerability in free5gc 3.3.0, UPF 1.2.0, and SMF 1.2.0 allows attackers to cause a denial of service via crafted PFCP messages.
- risk 0.49cvss 7.5epss 0.01
In Free5gc v3.0.5, the AMF breaks due to malformed NAS messages.
- risk 0.49cvss 7.5epss 0.03
Free5gc v3.2.1 is vulnerable to Information disclosure.
- risk 0.46cvss 8.2epss 0.00
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound OAuth2 middleware. On top of that, the DELETE /upi/v1/upNodesLinks/{upNodeRef} handler unconditionally dereferences upNode.UPF…
- risk 0.46cvss 8.2epss 0.00
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers and disclosure of subscriber SUPI. In NewServer(), the smPolicyGroup route group is…
- risk 0.45cvss —epss 0.00
free5GC is an open-source implementation of the 5G core network. In 4.2.3 and earlier, HandleCreateEeSubscriptions and HandleQueryeesubscriptions in free5gc/udr internal/sbi/api_datarepository.go validate the ueId path value with a regular expression whose final .+ alternative…
- risk 0.42cvss 7.5epss 0.00
An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of service via the UPF component
Page 2 of 6