F

Free5Gc Security Vulnerabilities (CVE)

Explore vulnerabilities and security advisories affecting Free5Gc products.

5 known CVE vulnerabilities tracked

Critical
0
High
3
Medium
2
Low
0
None
0

Vulnerabilities By Year

Products Affected

All Free5Gc CVEs

CVE-2026-41136
5.3 medium

free5GC AMF provides Access & Mobility Management Function (AMF) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. Prior to version 1.4.3, the `HTTPUEContextTransfer` handler in `internal/sbi/api_communication.go` does not include a `default` case in the `Content-T

Amf Apr 22, 2026
CVE-2026-41135
7.5 high

free5GC UDR is the Policy Control Function (PCF) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. A memory leak vulnerability in versions prior to 1.4.3 allows any unauthenticated attacker with network access to the PCF SBI interface to cause uncontrolled memory g

Free5Gc Apr 22, 2026
CVE-2026-40343
5.8 medium

free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.2, a fail-open request handling flaw in the UDR service causes the `/nudr-dr/v2/policy-data/subs-to-notify` POST handler to continue

Free5Gc Apr 22, 2026
CVE-2025-65562
7.5 high

The free5GC UPF suffers from a lack of bounds checking on the SEID when processing PFCP Session Deletion Requests. An unauthenticated remote attacker can send a request with a very large SEID (e.g., 0xFFFFFFFFFFFFFFFF) that causes an integer conversion/underflow in LocalNode.DeleteSess() / LocalNode

Free5Gc Dec 18, 2025
CVE-2025-65561
7.5 high

An issue was discovered in function LocalNode.Sess in free5GC 4.1.0 allowing attackers to cause a denial of service or other unspecified impacts via crafted header Local SEID to the PFCP Session Modification Request.

Free5Gc Dec 18, 2025