Skip to main content

Vendor archive

free5gc CVEs

Beta · best-effort

82 CVEs tagged to vendor free5gc7 Critical, 37 High, 33 Medium, 5 Low, 0 Unrated.

CVE-2026-2525

Published Feb 16, 2026

A vulnerability has been found in Free5GC up to 4.1.0. This affects an unknown function of the component PFCP UDP Endpoint. Such manipulation leads to denial of service. The attac…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
26.0
Vendor/product tagsBeta · best-effort

CVE-2025-70123

Published Feb 13, 2026

An improper input validation and protocol compliance vulnerability in free5GC v4.0.1 allows remote attackers to cause a denial of service. The UPF incorrectly accepts a malformed…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-70122

Published Feb 13, 2026

A heap buffer overflow vulnerability in the UPF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted PFCP Session Modification Request. T…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-70121

Published Feb 13, 2026

An array index out of bounds vulnerability in the AMF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted 5GS Mobile Identity in a NAS R…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2026-1976

Published Feb 6, 2026

A weakness has been identified in Free5GC up to 4.1.0. Affected is the function SessionDeletionResponse of the component SMF. This manipulation causes null pointer dereference. Th…

CVSS 5.5 · Medium
evidence mentions
7
Buzz score
27.3
Vendor/product tagsBeta · best-effort

CVE-2026-1975

Published Feb 6, 2026

A security flaw has been discovered in Free5GC up to 4.1.0. This impacts the function identityTriggerType of the file pfcp_reports.go. The manipulation results in null pointer der…

CVSS 5.5 · Medium
evidence mentions
7
Buzz score
27.3
Vendor/product tagsBeta · best-effort

CVE-2026-1974

Published Feb 6, 2026

A vulnerability was identified in Free5GC up to 4.1.0. This affects the function ResolveNodeIdToIp of the file internal/sbi/processor/datapath.go of the component SMF. The manipul…

CVSS 5.5 · Medium
evidence mentions
7
Buzz score
27.3
Vendor/product tagsBeta · best-effort

CVE-2026-1973

Published Feb 6, 2026

A vulnerability was determined in Free5GC up to 4.1.0. The impacted element is the function establishPfcpSession of the component SMF. Executing a manipulation can lead to null po…

CVSS 5.5 · Medium
evidence mentions
7
Buzz score
27.3
Vendor/product tagsBeta · best-effort

CVE-2026-1739

Published Feb 2, 2026

A vulnerability has been found in Free5GC pcf up to 1.4.1. This affects the function HandleCreateSmPolicyRequest of the file internal/sbi/processor/smpolicy.go. The manipulation l…

CVSS 5.5 · Medium
evidence mentions
8
Buzz score
28.5
Vendor/product tagsBeta · best-effort

CVE-2026-1684

Published Jan 30, 2026

A vulnerability was found in Free5GC SMF up to 4.1.0. Affected by this issue is the function HandleReports of the file /internal/context/pfcp_reports.go of the component PFCP UDP…

CVSS 6.9 · Medium
evidence mentions
7
Buzz score
27.3
Vendor/product tagsBeta · best-effort

CVE-2026-1683

Published Jan 30, 2026

A vulnerability has been found in Free5GC SMF up to 4.1.0. Affected by this vulnerability is the function HandlePfcpSessionReportRequest of the file internal/pfcp/handler/handler.…

CVSS 5.5 · Medium
evidence mentions
8
Buzz score
28.5
Vendor/product tagsBeta · best-effort

CVE-2026-1682

Published Jan 30, 2026

A flaw has been found in Free5GC SMF up to 4.1.0. Affected is the function HandlePfcpAssociationReleaseRequest of the file internal/pfcp/handler/handler.go of the component PFCP U…

CVSS 5.5 · Medium
evidence mentions
8
Buzz score
28.5
Vendor/product tagsBeta · best-effort

CVE-2025-66720

Published Jan 23, 2026

Null pointer dereference in free5gc pcf 1.4.0 in file internal/sbi/processor/ampolicy.go in function HandleDeletePoliciesPolAssoId.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66719

Published Jan 23, 2026

An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck() function in file internal/sbi/processor/access_token.go…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-65562

Published Dec 18, 2025

The free5GC UPF suffers from a lack of bounds checking on the SEID when processing PFCP Session Deletion Requests. An unauthenticated remote attacker can send a request with a ver…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-65561

Published Dec 18, 2025

An issue was discovered in function LocalNode.Sess in free5GC 4.1.0 allowing attackers to cause a denial of service or other unspecified impacts via crafted header Local SEID to t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-60638

Published Nov 24, 2025

An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Nnssf_NSSAIAvailability API.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-60633

Published Nov 24, 2025

An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via the Nudm_SubscriberDataManagement API.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-60632

Published Nov 24, 2025

An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Npcf_BDTPolicyControl API.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-63679

Published Nov 12, 2025

free5gc v4.1.0 and before is vulnerable to Buffer Overflow. When AMF receives an UplinkRANConfigurationTransfer NGAP message from a gNB, the AMF process crashes.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-56394

Published Sep 23, 2025

Free5gc 4.0.1 is vulnerable to Buffer Overflow. The AMF incorrectly validates the 5GS mobile identity, resulting in slice reference overflow.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-29632

Published May 29, 2025

Buffer Overflow vulnerability in Free5gc v.4.0.0 allows a remote attacker to cause a denial of service via the AMF, NGAP, security.go, handler_generated.go, handleInitialUEMessage…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49391

Published Dec 22, 2023

An issue was discovered in free5GC version 3.3.0, allows remote attackers to execute arbitrary code and cause a denial of service (DoS) on AMF component via crafted NGAP message.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47025

Published Nov 16, 2023

An issue in Free5gc v.3.3.0 allows a local attacker to cause a denial of service via the free5gc-compose component.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47347

Published Nov 15, 2023

Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP messages whose Sequence Number is mutated to overflow bytes.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 51-75 of 82 CVEsPage 3 of 4