← Back

Free5gc

free5gc

82 CVEs • 9 products

Products (9)

Click to collapse
Toggle
Free5gc
free5gc
Udm
udm
Smf
smf
Udr
udr
Pcf
pcf
Go Upf
go-upf
Amf
amf
Upf
upf
Nrf
nrf

CVEs (82)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Free5gc
1Free5gc
Jun 17, 2026
Jan 30, 2026
5.5 MEDIUM· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability has been found in Free5GC SMF up to 4.1.0. Affected by this vulnerability is the function HandlePfcpSessionReportRequest of the file internal/pfcp/handler/handler.go of the component PFCP. The manipulatio...Show more
A vulnerability has been found in Free5GC SMF up to 4.1.0. Affected by this vulnerability is the function HandlePfcpSessionReportRequest of the file internal/pfcp/handler/handler.go of the component PFCP. The manipulation leads to denial of service. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. To fix this issue, it is recommended to deploy a patch.Show less
1Free5gc
1Free5gc
Jun 17, 2026
Jan 30, 2026
5.5 MEDIUM· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw has been found in Free5GC SMF up to 4.1.0. Affected is the function HandlePfcpAssociationReleaseRequest of the file internal/pfcp/handler/handler.go of the component PFCP UDP Endpoint. Executing a manipulation can...Show more
A flaw has been found in Free5GC SMF up to 4.1.0. Affected is the function HandlePfcpAssociationReleaseRequest of the file internal/pfcp/handler/handler.go of the component PFCP UDP Endpoint. Executing a manipulation can lead to null pointer dereference. The attack may be launched remotely. The exploit has been published and may be used. A patch should be applied to remediate this issue.Show less
1Free5gc
1Pcf
Jun 17, 2026
Jan 23, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Null pointer dereference in free5gc pcf 1.4.0 in file internal/sbi/processor/ampolicy.go in function HandleDeletePoliciesPolAssoId.
1Free5gc
1Nrf
Jun 17, 2026
Jan 23, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck() function in file internal/sbi/processor/access_token.go bypasses all scope validation when the at...Show more
An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck() function in file internal/sbi/processor/access_token.go bypasses all scope validation when the attacker uses a crafted targetNF value. This allows attackers to obtain an access token with any arbitrary scope.Show less
1Free5gc
1Free5gc
Jun 17, 2026
Dec 18, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
The free5GC UPF suffers from a lack of bounds checking on the SEID when processing PFCP Session Deletion Requests. An unauthenticated remote attacker can send a request with a very large SEID (e.g., 0xFFFFFFFFFFFFFFFF) t...Show more
The free5GC UPF suffers from a lack of bounds checking on the SEID when processing PFCP Session Deletion Requests. An unauthenticated remote attacker can send a request with a very large SEID (e.g., 0xFFFFFFFFFFFFFFFF) that causes an integer conversion/underflow in LocalNode.DeleteSess() / LocalNode.Sess() when a uint64 SEID is converted to int and used in index arithmetic. This leads to a negative index into n.sess and a Go runtime panic, resulting in a denial of service (UPF crash). The issue has been reproduced on free5GC v4.1.0 with crashes observed in the session lookup/deletion path in internal/pfcp/node.go; other versions may also be affected. No authentication is required.Show less
1Free5gc
1Free5gc
Jun 17, 2026
Dec 18, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in function LocalNode.Sess in free5GC 4.1.0 allowing attackers to cause a denial of service or other unspecified impacts via crafted header Local SEID to the PFCP Session Modification Request.
1Free5gc
1Free5gc
Jun 17, 2026
Nov 24, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Nnssf_NSSAIAvailability API.
1Free5gc
1Free5gc
Jun 17, 2026
Nov 24, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via the Nudm_SubscriberDataManagement API.
1Free5gc
1Free5gc
Jun 17, 2026
Nov 24, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Npcf_BDTPolicyControl API.
1Free5gc
1Free5gc
Jun 17, 2026
Nov 12, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
free5gc v4.1.0 and before is vulnerable to Buffer Overflow. When AMF receives an UplinkRANConfigurationTransfer NGAP message from a gNB, the AMF process crashes.
1Free5gc
1Free5gc
Jun 17, 2026
Sep 23, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Free5gc 4.0.1 is vulnerable to Buffer Overflow. The AMF incorrectly validates the 5GS mobile identity, resulting in slice reference overflow.
1Free5gc
1Free5gc
Jun 17, 2026
May 29, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Buffer Overflow vulnerability in Free5gc v.4.0.0 allows a remote attacker to cause a denial of service via the AMF, NGAP, security.go, handler_generated.go, handleInitialUEMessageMain, DecodePlainNasNoIntegrityCheck, Get...Show more
Buffer Overflow vulnerability in Free5gc v.4.0.0 allows a remote attacker to cause a denial of service via the AMF, NGAP, security.go, handler_generated.go, handleInitialUEMessageMain, DecodePlainNasNoIntegrityCheck, GetSecurityHeaderType componentsShow less
1Free5gc
1Free5gc
Jun 17, 2026
Dec 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in free5GC version 3.3.0, allows remote attackers to execute arbitrary code and cause a denial of service (DoS) on AMF component via crafted NGAP message.
1Free5gc
1Free5gc
Jun 17, 2026
Nov 16, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue in Free5gc v.3.3.0 allows a local attacker to cause a denial of service via the free5gc-compose component.
1Free5gc
1Free5gc
Jun 17, 2026
Nov 15, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP messages whose Sequence Number is mutated to overflow bytes.
1Free5gc
1Free5gc
Jun 17, 2026
Nov 15, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP message with malformed PFCP Heartbeat message whose Recovery Time Stamp IE length is mutated to zero.
1Free5gc
3Free5gc
SmfUpf
Jun 17, 2026
Nov 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Buffer Overflow vulnerability in free5gc 3.3.0, UPF 1.2.0, and SMF 1.2.0 allows attackers to cause a denial of service via crafted PFCP messages.
1Free5gc
1Udm
Jun 17, 2026
Oct 23, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via an uncompressed public key that has not been validated. An attacker can...Show more
pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via an uncompressed public key that has not been validated. An attacker can send arbitrary SUCIs to the UDM, which tries to decrypt them via both its private key and the attacker's public key.Show less
1Free5gc
1Free5gc
Jun 17, 2026
Oct 2, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Cross-Site Request Forgery vulnerability, whose exploitation could allow an attacker to perform different actions on the platform as an administrator, simply by changing the token value to "admin". It is also possible to...Show more
Cross-Site Request Forgery vulnerability, whose exploitation could allow an attacker to perform different actions on the platform as an administrator, simply by changing the token value to "admin". It is also possible to perform POST, GET and DELETE requests without any token value. Therefore, an unprivileged remote user is able to create, delete and modify users within theapplication.Show less
1Free5gc
1Free5gc
Jun 17, 2026
Nov 18, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
In Free5gc v3.0.5, the AMF breaks due to malformed NAS messages.