Vulnerabilidades em free5gc
58 resultadosAnálise Vexday
Free5gc apresenta 48 vulnerabilidades catalogadas, com 20 divulgadas nos últimos 90 dias, indicando ritmo significativo de descobertas. Embora nenhuma esteja sob exploração ativa conhecida (KEV), 5 são críticas, sendo CWE-476 (null pointer dereference) o padrão predominante, sugerindo falhas sistemáticas em validação de entrada que demandam atenção imediata para implementações em produção.
CVE-2026-44329CRITICALfree5GC: SMF UPI management interface lacks auth middleware; unauthenticated topology read/write requests reach handlersEPSS 0.6%CVE-2026-32937HIGHfree5GC CHF has Out-of-Bounds Slice Access that Leads to DoSEPSS 0.6%CVE-2025-69247LOWfree5GC has Heap Buffer Overflow in UPF Leading to Denial of ServiceEPSS 0.5%CVE-2026-42083HIGHfree5GC: PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers and disclosure of subscriber SUPIEPSS 0.5%CVE-2026-44328HIGHfree5GC: SMF UPI DELETE /upi/v1/upNodesLinks/{ref} panics on AN-node deletion via nil UPF dereference; unauthenticated, state-mutatingEPSS 0.5%CVE-2026-47780MEDIUMfree5GC: UDR Improper ueId validation in free5GC EE subscription handlers allows arbitrary identifier persistenceEPSS 0.5%CVE-2026-41135HIGHfree5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of ServiceEPSS 0.5%CVE-2026-1684MEDIUMFree5GC SMF PFCP UDP Endpoint pfcp_reports.go HandleReports denial of serviceEPSS 0.5%CVE-2026-44327CRITICALfree5GC: NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handlerEPSS 0.5%CVE-2025-69252MEDIUMfree5GC has Null Pointer Dereference in UDM, Leading to Service PanicEPSS 0.5%CVE-2026-44315CRITICALfree5GC: NEF 3gpp-pfd-management API is unauthenticated; forged bearer tokens can create, read, and delete PFD transactionsEPSS 0.5%CVE-2026-44326CRITICALfree5GC: NEF 3gpp-traffic-influence API is unauthenticated; missing or forged bearer tokens can create, read, patch, and delete subscriptionsEPSS 0.5%CVE-2026-26024MEDIUMfree5GC SMF crash (nil pointer dereference) on PFCP SessionReportRequest when ReportType.USAR=1 and UsageReport omits mandatory URRID sub-IE EPSS 0.5%CVE-2026-26025MEDIUMfree5GC SMF crash (nil pointer dereference) on PFCP SessionReportRequest when ReportType.USAR=1 and UsageReport omits mandatory URRID sub-IE EPSS 0.5%CVE-2026-25501MEDIUMfree5GC SMF crash (nil pointer dereference) on PFCP SessionReportRequest when ReportType.DLDR is set but DownlinkDataReport IE is missingEPSS 0.5%CVE-2026-40247HIGHfree5gc UDR improper path validation allows unauthenticated access to Traffic Influence SubscriptionsEPSS 0.5%CVE-2026-40248HIGHfree5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence SubscriptionsEPSS 0.5%CVE-2025-69251MEDIUMfree5GC has Improper Input Validation in UDM, Leading to Information ExposureEPSS 0.5%CVE-2026-40246HIGHfree5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence SubscriptionsEPSS 0.4%CVE-2026-42459HIGHfree5GC: Improper Input Validation and Generation of Error Message Containing Sensitive Information in github.com/free5gc/udmEPSS 0.4%