Vulnerabilidades em Free5GC
58 resultadosAnálise Vexday
Free5GC apresenta footprint reduzido de vulnerabilidades (4 CVEs totais) sem registros de exploração ativa no campo. Nenhuma vulnerabilidade crítica foi identificada, e o risco não apresenta movimento recente, indicando panorama de segurança estável. A fraqueza dominante catalogada (CWE-404 - Improper Resource Validation) sugere falhas pontuais em validação, porém com baixa urgência operacional no contexto atual.
CVE-2026-33062HIGHfree5GC NRF Discovery EncodeGroupId Function Panics on Malformed group-id-list ParameterEPSS 1.0%CVE-2026-33063HIGHfree5GC AUSF UE Authentication Panic on Nil SuciSupiMap Interface ConversionEPSS 0.9%CVE-2026-33064HIGHfree5GC UDM DataChangeNotification Procedure Panic Due to Nil Pointer DereferenceEPSS 0.8%CVE-2026-1739MEDIUMFree5GC pcf smpolicy.go HandleCreateSmPolicyRequest null pointer dereferenceEPSS 0.7%CVE-2026-53551MEDIUMfree5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failureEPSS 0.7%CVE-2026-1682MEDIUMFree5GC SMF PFCP UDP Endpoint handler.go HandlePfcpAssociationReleaseRequest null pointer dereferenceEPSS 0.7%CVE-2026-44324MEDIUMfree5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request)EPSS 0.7%CVE-2026-1683MEDIUMFree5GC SMF PFCP handler.go HandlePfcpSessionReportRequest denial of serviceEPSS 0.7%CVE-2026-44319HIGHfree5GC: NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-controlled notifyUri)EPSS 0.7%CVE-2026-44316HIGHfree5GC: PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereferenceEPSS 0.7%CVE-2026-44322HIGHfree5GC: NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR access failure due to nil ProblemDetails dereferenceEPSS 0.7%CVE-2026-44325HIGHfree5GC: NRF POST /oauth2/token structured-form parser type-confusion panic family (Reflect.Set on incompatible types)EPSS 0.7%CVE-2026-27642MEDIUMfree5GC has Improper Input Validation in UDM UEAU ServiceEPSS 0.7%CVE-2026-44321HIGHfree5GC: SMF UPI POST /upi/v1/upNodesLinks exits the SMF process on overlapping UE pools (unauthenticated, reachable Fatalf)EPSS 0.6%CVE-2026-55068CRITICALfree5GC: NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpointsEPSS 0.6%CVE-2025-69248MEDIUMfree5GC has Array Index Out of Bounds in AMF Leading to Denial of ServiceEPSS 0.6%CVE-2026-44317MEDIUMfree5GC: PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereferenceEPSS 0.6%CVE-2026-44323MEDIUMfree5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference)EPSS 0.6%CVE-2026-33191HIGHfree5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server ErrorEPSS 0.6%CVE-2026-40245HIGHFree5GC: UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authenticationEPSS 0.6%