PatchSiren

free5gc CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH free5gc CVE published 2026-05-27

CVE-2026-44316

A nil-pointer dereference in free5GC's Policy Control Function (PCF) allows unauthenticated remote attackers to trigger a panic via a crafted POST request to the SM Policy Control endpoint. The vulnerability exists in versions prior to 4.2.2, where the HandleCreateSmPolicyRequest handler fails to properly handle 404 responses from downstream UDR lookups. When the OpenAPI consumer wrapper returns an error [truncated]

CRITICAL free5gc CVE published 2026-05-27

CVE-2026-44315

free5GC is an open-source implementation of the 5G core network. Prior to version 4.2.2, the Network Exposure Function (NEF) component mounts the 3gpp-pfd-management API without enforcing inbound OAuth2/bearer-token authorization. A network attacker with reachability to the NEF on the Service-Based Interface (SBI) can create, read, and delete PFD-management transaction state using a forged or arbitrary be [truncated]

HIGH free5gc CVE published 2026-05-27

CVE-2026-42459

free5GC UDM (Unified Data Management) component prior to version 4.2.2 contains an input validation vulnerability in the nudm-sdm (Subscriber Data Management) service. Six GET handlers fail to properly validate the supi path parameter, allowing unauthenticated attackers to inject control characters into the SUPI (Subscription Permanent Identifier) parameter. This injection causes UDM to forward malformed [truncated]

HIGH free5gc CVE published 2026-05-27

CVE-2026-42083

free5GC prior to version 4.2.2 contains a missing authentication vulnerability in the PCF (Policy Control Function) Npcf_SMPolicyControl service. The smPolicyGroup route group is registered without the RouterAuthorizationCheck middleware, allowing unauthenticated network requests to reach SM policy business logic. Affected endpoints include /npcf-smpolicycontrol/v1/sm-policies and related sub-resources. T [truncated]

LOW free5gc CVE published 2026-05-27

CVE-2026-42082

A vulnerability in free5GC's Access and Mobility Management Function (AMF) prior to version 4.2.2 allows security context mismatches between the network and User Equipment (UE). The AMF fails to enforce concurrent security procedure rules from 3GPP TS 33.501 §6.9.5.1, specifically not checking for ongoing N2 handover procedures before initiating NAS Security Mode Command, and vice versa. This can result i [truncated]

MEDIUM free5gc CVE published 2026-05-27

CVE-2026-42081

A medium-severity vulnerability in free5GC's Access and Mobility Management Function (AMF) allows malicious gNodeBs to overwrite UE security capabilities, causing persistent handover denial-of-service. The AMF fails to validate UE Security Capabilities in NGAP PathSwitchRequest messages against locally stored values as required by 3GPP TS 33.501 §6.7.3.1. Arbitrary values propagate through PathSwitchReque [truncated]