These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A vulnerability was determined in Free5GC up to 4.2.3, affecting unknown code in the file /corefuzzer_deps/free5gc/NFs/amf/internal/gmm/handler.go of the Gmm Handler component. This manipulation causes a race condition, which can be initiated remotely. The patch name is e323b01464355781b8b8d5dd695e05cbc00a62f2. Defenders should assess exposure and apply the patch. The vulnerability allows remote attackers [truncated]
CVE-2026-75439 is a high-severity denial-of-service vulnerability in Free5GC v4.2.2 via the UPF component. Defenders should assess exposure and prioritize verification of potential denial-of-service attacks. The vulnerability affects Free5GC deployments, particularly those using UPF components. Verification of Free5GC v4.2.2 deployments is necessary to determine exposure. Remediation or mitigation strateg [truncated]
The free5GC AUSF component is vulnerable to a timing side-channel attack due to insecure cryptographic authentication comparisons. This issue allows attackers to potentially exploit timing discrepancies, although practical remote exploitation was not demonstrated. The vulnerability is fixed in version 1.4.5. Affected product deployments should be identified and verified for exposure. Official advisories a [truncated]
PatchSiren debrief for CVE-2026-55784: free5GC AUSF component authentication denial of service. The free5GC AUSF component stores per-subscriber authentication state in a global sync.Map. An attacker with access to the AUSF SBI/N12 interface can send concurrent POST /nausf-auth/v1/ue-authentications requests for the same target SUPI, causing all attempts to share one logical authentication context URL whi [truncated]
A critical vulnerability exists in free5GC, an open-source implementation of the 5G core network, specifically in versions 4.2.2 and earlier. The NRF RegisterNFInstance handler at PUT /nnrf-nfm/v1/nf-instances/{nfInstanceID} does not enforce proper validation on NF Profiles, allowing an attacker with SBI access to advertise malicious network-function endpoints. This can lead to exposure of credentials and [truncated]
The CVE-2026-30073 record details a Denial of Service (DoS) vulnerability in the NssaiAvailabilitySubscriptionCreate component of free5gc v4.0.1. This vulnerability can be exploited via a crafted POST request. Organizations using free5gc v4.0.1 should be aware of this vulnerability and take necessary actions to mitigate it. The CVE record was published on 2026-08-27T17:17:52.443Z and has not been modified [truncated]
A NULL pointer dereference vulnerability exists in the CDR processing path of free5gc v4.0.1. This allows attackers to cause a Denial of Service (DoS) by supplying a crafted payload. The vulnerability has a HIGH CVSS score of 7.5, indicating a significant threat. Organizations using free5gc v4.0.1 should be aware of this vulnerability and take steps to mitigate it, including reviewing system configuration [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T17:17:52.090Z and has not been modified since then. The vulnerability affects free5gc v4.0.1 and allows attackers to cause a Denial of Service (DoS) via a crafted input. Users of free5gc v4.0.1 should review and apply vendor patches to prevent potential Denial of Service attacks. Limited evidence [truncated]
A NULL pointer dereference in the UDMC registration handler component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted payload. This vulnerability impacts free5gc deployments, specifically affecting the UDMC registration handler. The vulnerability class is related to improper handling of NULL pointer dereferences. The likely operational impact includes service di [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T17:17:51.857Z and has not been modified since then. The HandleUpdate function in free5gc v4.0.1 contains an improper input validation vulnerability, which could allow attackers to cause a Denial of Service (DoS) via crafted input. This vulnerability has a CVSS score of 7.5 and is classified as HI [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T17:17:51.740Z and has not been modified since then. The vulnerability affects free5gc v4.0.1 and is classified as a Denial of Service (DoS) vulnerability in the complexQueryFilterSubprocess function of the NRF Discovery service. The vulnerability has a HIGH severity score of 7.5. Teams using free [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T17:17:51.260Z and has not been modified since then. Organizations using free5gc v4.0.1 should review and verify their systems for potential vulnerability. This review should be conducted with caution due to limited source detail and potential for unknown affected scope. Additional verification ta [truncated]
The CVE-2026-30058 record details an Improper Input Validation vulnerability in the HTTPModifySubscription handler of free5gc v4.0.1. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. Organizations should verify their inventory and apply vendor remediation if available. The CVE record was published on 2026-08-27T17:17:51.020Z and has not been modified since then. [truncated]
An AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T17:17:50.897Z and has not been modified since then. This CVE-2026-30057 issue in the CreateUEContext handler component of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted request. Security teams should assess affected systems and implement compensating [truncated]
A NULL pointer dereference in the AMF NGAP Dispatcher component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted NGAP messages during the initialization of a new RAN connection. This vulnerability is particularly concerning for networks relying on free5gc for their 5G infrastructure, as it could lead to service disruptions. Administrators should be aware of the p [truncated]
The free5GC AUSF component does not validate the supiOrSuci field in UE authentication requests, allowing null bytes and control characters to pass through JSON parsing. This causes a failure in Go's net/url.Parse(), resulting in an HTTP 500 error and leaked internal stack traces. An unauthenticated attacker can trigger this vulnerability at scale, causing denial of service for all subscribers attempting [truncated]
CVE-2026-44330 is a critical authentication bypass vulnerability in free5GC, an open-source 5G core network implementation. The Network Exposure Function (NEF) component mounts the nnef-pfdmanagement route group without inbound OAuth2/bearer-token authorization, allowing unauthenticated network attackers to read Packet Flow Description (PFD) application data and manipulate PFD change-notification subscrip [truncated]
free5GC's Session Management Function (SMF) component prior to version 4.2.2 exposes UPI (User Plane Infrastructure) management endpoints without requiring OAuth2 or bearer-token authentication. An unauthenticated network attacker with reachability to the SMF Service-Based Interface (SBI) can perform read, write, and delete operations on UP-node and link configurations. The vulnerability stems from the UP [truncated]
free5GC's Session Management Function (SMF) prior to version 4.2.2 contains an unauthenticated denial-of-service vulnerability in its UPI (User Plane Interface) management API. The DELETE /upi/v1/upNodesLinks/{upNodeRef} endpoint lacks OAuth2 authentication middleware and contains a nil-pointer dereference flaw. When processing a deletion request for an Access Node (AN)-type entry—such as a gNB—the handle [truncated]
## Summary free5GC NEF (Network Exposure Function) prior to version 4.2.2 exposes the `nnef-oam` route group without OAuth2/bearer-token authorization. A network attacker with reachability to the NEF Service-Based Interface (SBI) can access OAM (Operations, Administration, and Maintenance) endpoints without providing any Authorization header, receiving HTTP 200 OK responses. While the current OAM handler [truncated]
A critical authentication bypass vulnerability in free5GC's Network Exposure Function (NEF) allows unauthenticated network attackers to manipulate 5G traffic steering subscriptions. The 3gpp-traffic-influence API endpoint lacks OAuth2/bearer-token authorization enforcement, permitting arbitrary create, read, patch, and delete operations on traffic-influence subscriptions—including AnyUeInd=true subscripti [truncated]
A type-confusion vulnerability in free5GC's Network Repository Function (NRF) allows unauthenticated remote attackers to trigger panics via the OAuth2 token endpoint. The root cause is unsafe reflection in the SBI access token handler that assumes all non-string, non-NfType fields in the token request struct are of type models.PlmnId. When an attacker submits form-encoded data with field names whose actua [truncated]
A nil-pointer dereference panic in free5GC's UDR (Unified Data Repository) component allows authenticated attackers to repeatedly crash the service via a crafted DELETE request. The vulnerability exists in the nudr-dr endpoint handler for `/subscription-data/{ueId}/{servingPlmnId}/ee-subscriptions/{subsId}/amf-subscriptions`. When a request specifies a non-existent UE ID, the handler correctly identifies [truncated]
A nil-pointer dereference vulnerability exists in free5GC's UDR (Unified Data Repository) component prior to version 4.2.2. The affected endpoint is the nudr-dr DELETE handler for `/subscription-data/{ueId}/{servingPlmnId}/ee-subscriptions/{subsId}/amf-subscriptions`. The handler performs a map lookup for `UESubsData.EeSubscriptionCollection[subsId]` and correctly detects a miss, setting a 404 problem-det [truncated]
A nil-pointer dereference vulnerability in free5GC's Network Exposure Function (NEF) prior to version 4.2.2 allows unauthenticated remote attackers to trigger a panic and HTTP 500 error response. The flaw exists in the PATCH /3gpp-pfd-management/v1/{afId}/transactions/{transId}/applications/{appId} endpoint handler. When an upstream UDR (Unified Data Repository) call fails and the consumer wrapper returns [truncated]
free5GC's Session Management Function (SMF) component prior to version 4.2.2 exposes an unauthenticated management endpoint that can trigger a fatal process termination. The UPI (User Plane Infrastructure) management route group at POST /upi/v1/upNodesLinks lacks OAuth2 middleware, allowing unauthenticated attackers to submit JSON payloads. When the handler processes attacker-controlled input through UpNo [truncated]
free5GC NEF (Network Exposure Function) prior to version 4.2.2 fails to enforce OAuth2/bearer-token authorization on the nnef-callback route group. An attacker can submit forged callback requests with arbitrary bearer tokens to reach SMF-callback handlers and manipulate subscription state if a valid NotifId is known or guessed. The vulnerability stems from missing inbound authentication middleware on the [truncated]
A critical availability vulnerability in free5GC's Network Exposure Function (NEF) allows unauthenticated remote attackers to terminate the entire NEF process via a malformed PFD subscription. The flaw resides in PfdChangeNotifier.FlushNotifications(), where delivery failures to a subscriber's notifyUri trigger a fatal log call equivalent to os.Exit(1), causing immediate process termination with status 1. [truncated]
A race condition in free5GC's Binding Support Function (BSF) prior to version 4.2.2 allows authenticated attackers to trigger a fatal runtime panic and denial-of-service condition. The vulnerability exists in the PUT /nbsf-management/v1/subscriptions/{subId} handler where concurrent map access occurs: the handler reads from a global Subscriptions map under RLock(), but when a subscription does not exist, [truncated]
A nil pointer dereference vulnerability in free5GC's Policy Control Function (PCF) allows authenticated attackers to trigger a denial of service via a crafted API request. The flaw exists in the POST /npcf-policyauthorization/v1/app-sessions handler prior to version 4.2.2. When processing application session creation requests with the traffic-routing feature enabled (suppFeat ==