VYPR

Vendor CVEs

Free5gc

All CVEs

127 total · sorted by risk
  • CVE-2026-8780MedMay 18, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was identified in omec-project amf up to 2.1.3-dev. The affected element is an unknown function of the file ngap/dispatcher.go of the component NGAP Message Handler. The manipulation leads to memory corruption. The attack may be initiated remotely. The exploit is…

  • CVE-2026-8779MedMay 18, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was determined in omec-project amf up to 2.1.3-dev. Impacted is the function NGSetupRequest of the file ngap/handler.go. Executing a manipulation of the argument InformationElement can lead to memory corruption. The attack can be launched remotely. The exploit…

  • CVE-2026-8349MedMay 12, 2026
    risk 0.21cvss 4.3epss 0.00

    A flaw has been found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGAP Message Handler. Executing a manipulation can lead to memory corruption. The attack can be launched remotely. The exploit has been published and may be used. This…

  • CVE-2026-55785LowAug 28, 2026
    risk 0.17cvss 3.7epss 0.00

    free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the AUSF component performs cryptographic authentication comparisons in internal/sbi/processor/ue_authentication.go with ordinary equality helpers. Auth5gAkaComfirmRequestProcedure compares RES* and…

  • CVE-2026-42082LowMay 27, 2026
    risk 0.17cvss 3.7epss 0.00

    free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not enforce the concurrent security procedure rules defined in 3GPP TS 33.501 §6.9.5.1. The AMF does not check for ongoing N2 handover procedures before initiating a NAS…

  • CVE-2026-5360LowApr 2, 2026
    risk 0.17cvss 3.7epss 0.00

    A vulnerability has been found in Free5GC 4.2.0. The affected element is an unknown function of the component aper. Such manipulation leads to type confusion. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is described as…

  • CVE-2026-27643MedFeb 24, 2026
    risk 0.00cvss 5.3epss 0.00

    free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, the NEF component reliably leaks internal parsing error details (e.g., invalid character 'n' after top-level…

  • CVE-2026-27642HigFeb 24, 2026
    risk 0.00cvss 7.5epss 0.01

    free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, remote attackers can inject control characters (e.g., %00) into the supi parameter, triggering internal URL…

  • CVE-2025-69253MedFeb 24, 2026
    risk 0.00cvss 5.3epss 0.00

    free5GC is an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 of the User Data Repository are affected by Improper Error Handling with Information Exposure. The NEF component reliably leaks internal parsing error details…

  • CVE-2025-69252HigFeb 24, 2026
    risk 0.00cvss 7.5epss 0.01

    free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 have a NULL Pointer Dereference vulnerability. Remote unauthenticated attackers can trigger a service panic…

  • CVE-2025-69251MedFeb 24, 2026
    risk 0.00cvss 5.3epss 0.00

    free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, remote attackers can inject control characters (e.g., %00) into the ueId parameter, triggering internal URL…

  • CVE-2025-69250HigFeb 24, 2026
    risk 0.00cvss 7.5epss 0.00

    free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, the service reliably leaks detailed internal error messages (e.g., strconv.ParseInt parsing errors) to…

  • CVE-2025-69248HigFeb 23, 2026
    risk 0.00cvss 7.5epss 0.01

    free5GC is an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 of free5GC's AMF service have a Buffer Overflow vulnerability leading to Denial of Service. Remote unauthenticated attackers can crash the AMF service by sending a…

  • CVE-2025-69247HigFeb 23, 2026
    risk 0.00cvss 7.5epss 0.01

    free5GC go-upf is the User Plane Function (UPF) implementation for 5G networks that is part of the free5GC project. Versions prior to 1.2.8 have a Heap-based Buffer Overflow (CWE-122) vulnerability leading to Denial of Service. Remote attackers can crash the UPF network element…

  • CVE-2025-69208MedFeb 23, 2026
    risk 0.00cvss 5.3epss 0.00

    free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. Versions prior to 1.4.1 contain an Improper Error Handling vulnerability with Information Exposure. All deployments of free5GC using the…

  • CVE-2026-1976MedFeb 6, 2026
    risk 0.00cvss 5.3epss 0.01

    A weakness has been identified in Free5GC up to 4.1.0. Affected is the function SessionDeletionResponse of the component SMF. This manipulation causes null pointer dereference. The attack is possible to be carried out remotely. The exploit has been made available to the public…

  • CVE-2026-1975MedFeb 6, 2026
    risk 0.00cvss 5.3epss 0.01

    A security flaw has been discovered in Free5GC up to 4.1.0. This impacts the function identityTriggerType of the file pfcp_reports.go. The manipulation results in null pointer dereference. The attack can be executed remotely. The exploit has been released to the public and may…

  • CVE-2026-1974MedFeb 6, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was identified in Free5GC up to 4.1.0. This affects the function ResolveNodeIdToIp of the file internal/sbi/processor/datapath.go of the component SMF. The manipulation leads to denial of service. Remote exploitation of the attack is possible. The exploit is…

  • CVE-2026-1973MedFeb 6, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was determined in Free5GC up to 4.1.0. The impacted element is the function establishPfcpSession of the component SMF. Executing a manipulation can lead to null pointer dereference. The attack may be launched remotely. The exploit has been publicly disclosed and…

  • CVE-2026-1739MedFeb 2, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability has been found in Free5GC pcf up to 1.4.1. This affects the function HandleCreateSmPolicyRequest of the file internal/sbi/processor/smpolicy.go. The manipulation leads to null pointer dereference. The attack is possible to be carried out remotely. The exploit has…

  • CVE-2026-1684MedJan 30, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was found in Free5GC SMF up to 4.1.0. Affected by this issue is the function HandleReports of the file /internal/context/pfcp_reports.go of the component PFCP UDP Endpoint. The manipulation results in denial of service. The attack can be executed remotely. It is…

  • CVE-2026-1683MedJan 30, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability has been found in Free5GC SMF up to 4.1.0. Affected by this vulnerability is the function HandlePfcpSessionReportRequest of the file internal/pfcp/handler/handler.go of the component PFCP. The manipulation leads to denial of service. Remote exploitation of the…

  • CVE-2026-1682MedJan 30, 2026
    risk 0.00cvss 5.3epss 0.01

    A flaw has been found in Free5GC SMF up to 4.1.0. Affected is the function HandlePfcpAssociationReleaseRequest of the file internal/pfcp/handler/handler.go of the component PFCP UDP Endpoint. Executing a manipulation can lead to null pointer dereference. The attack may be…

  • CVE-2025-66720HigJan 23, 2026
    risk 0.00cvss 7.5epss 0.00

    Null pointer dereference in free5gc pcf 1.4.0 in file internal/sbi/processor/ampolicy.go in function HandleDeletePoliciesPolAssoId.

  • CVE-2025-65564HigDec 18, 2025
    risk 0.00cvss 7.5epss 0.00

    A denial-of-service vulnerability exists in the omec-upf (upf-epc-pfcpiface) in version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Association Setup Request that is missing the mandatory Recovery Time Stamp Information Element, the association setup handler…

  • CVE-2025-65563HigDec 18, 2025
    risk 0.00cvss 7.5epss 0.00

    A denial-of-service vulnerability exists in the omec-project UPF (component upf-epc/pfcpiface) up to at least version upf-epc-pfcpiface:2.1.3-dev. When the UPF receives a PFCP Association Setup Request that is missing the mandatory NodeID Information Element, the association…

  • CVE-2025-65561HigDec 18, 2025
    risk 0.00cvss 7.5epss 0.00

    An issue was discovered in function LocalNode.Sess in free5GC 4.1.0 allowing attackers to cause a denial of service or other unspecified impacts via crafted header Local SEID to the PFCP Session Modification Request.

Page 3 of 3