Vulnerabilidades en free5gc
58 resultadosAnálisis Vexday
Free5gc apresenta 48 vulnerabilidades catalogadas, com 20 divulgadas nos últimos 90 dias, indicando ritmo significativo de descobertas. Embora nenhuma esteja sob exploração ativa conhecida (KEV), 5 são críticas, sendo CWE-476 (null pointer dereference) o padrão predominante, sugerindo falhas sistemáticas em validação de entrada que demandam atenção imediata para implementações em produção.
CVE-2026-33062HIGHfree5GC NRF Discovery EncodeGroupId Function Panics on Malformed group-id-list ParameterEPSS 1.0%CVE-2026-33063HIGHfree5GC AUSF UE Authentication Panic on Nil SuciSupiMap Interface ConversionEPSS 0.9%CVE-2026-33064HIGHfree5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer DereferenceEPSS 0.8%CVE-2026-1739MEDIUMFree5GC pcf smpolicy.go HandleCreateSmPolicyRequest null pointer dereferenceEPSS 0.7%CVE-2026-53551MEDIUMfree5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failureEPSS 0.7%CVE-2026-1682MEDIUMFree5GC SMF PFCP UDP Endpoint handler.go HandlePfcpAssociationReleaseRequest null pointer dereferenceEPSS 0.7%CVE-2026-44324MEDIUMfree5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request)EPSS 0.7%CVE-2026-1683MEDIUMFree5GC SMF PFCP handler.go HandlePfcpSessionReportRequest denial of serviceEPSS 0.7%CVE-2026-44319HIGHfree5GC: NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-controlled notifyUri)EPSS 0.7%CVE-2026-44316HIGHfree5GC: PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereferenceEPSS 0.7%CVE-2026-44322HIGHfree5GC: NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR access failure due to nil ProblemDetails dereferenceEPSS 0.7%CVE-2026-44325HIGHfree5GC: NRF POST /oauth2/token structured-form parser type-confusion panic family (Reflect.Set on incompatible types)EPSS 0.7%CVE-2026-27642MEDIUMfree5GC has Improper Input Validation in UDM UEAU ServiceEPSS 0.7%CVE-2026-44321HIGHfree5GC: SMF UPI POST /upi/v1/upNodesLinks exits the SMF process on overlapping UE pools (unauthenticated, reachable Fatalf)EPSS 0.6%CVE-2026-55068CRITICALfree5GC: NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpointsEPSS 0.6%CVE-2025-69248MEDIUMfree5GC has Array Index Out of Bounds in AMF Leading to Denial of ServiceEPSS 0.6%CVE-2026-44317MEDIUMfree5GC: PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereferenceEPSS 0.6%CVE-2026-44323MEDIUMfree5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference)EPSS 0.6%CVE-2026-33191HIGHfree5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server ErrorEPSS 0.6%CVE-2026-40245HIGHFree5GC: UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authenticationEPSS 0.6%