FREE5GC
72 CVEs tracked since 2023. Since Nov 2023, none of them reached CISA KEV.
FREE5GC CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2023-11 | 4 | 0 |
| 2023-12 | null or fewer | |
| 2024-01 | null or fewer | |
| 2024-02 | null or fewer | |
| 2024-03 | null or fewer | |
| 2024-04 | null or fewer | |
| 2024-05 | null or fewer | |
| 2024-06 | null or fewer | |
| 2024-07 | null or fewer | |
| 2024-08 | null or fewer | |
| 2024-09 | null or fewer | |
| 2024-10 | null or fewer | |
| 2024-11 | null or fewer | |
| 2024-12 | null or fewer | |
| 2025-01 | null or fewer | |
| 2025-02 | null or fewer | |
| 2025-03 | null or fewer | |
| 2025-04 | null or fewer | |
| 2025-05 | null or fewer | |
| 2025-06 | null or fewer | |
| 2025-07 | null or fewer | |
| 2025-08 | null or fewer | |
| 2025-09 | null or fewer | |
| 2025-10 | null or fewer | |
| 2025-11 | 4 | 0 |
| 2025-12 | null or fewer | |
| 2026-01 | 5 | 0 |
| 2026-02 | 22 | 0 |
| 2026-03 | 8 | 0 |
| 2026-04 | 9 | 0 |
| 2026-05 | 20 | 0 |
Products
The products that kept showing up in FREE5GC's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting FREE5GC.
- CVE-2026-47780free5GC: UDR Improper ueId validation in free5GC EE subscription handlers allows arbitrary identifier persistence—
- CVE-2026-55785free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA3.7
- CVE-2026-55784free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI7.5
- CVE-2026-55068free5GC: NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints—
- CVE-2026-53551free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure—
- CVE-2026-42081free5GC: UE Security Capability bypass on NGAP PathSwitchRequest6.1
- CVE-2026-42082free5GC: Missing Concurrent NAS SMC Validation During NGAP Handover3.7
- CVE-2026-42083free5GC: PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers and disclosure of subscriber SUPI8.2
- CVE-2026-42459free5GC: Improper Input Validation and Generation of Error Message Containing Sensitive Information in github.com/free5gc/udm7.5
- CVE-2026-44315free5GC: NEF 3gpp-pfd-management API is unauthenticated; forged bearer tokens can create, read, and delete PFD transactions9.4
- CVE-2026-44316free5GC: PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference7.5
- CVE-2026-44317free5GC: PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference6.5
- CVE-2026-44319free5GC: NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-controlled notifyUri)7.5
- CVE-2026-44320free5GC: NEF nnef-callback route group is unauthenticated; forged callback requests are accepted into the processing path7.3
- CVE-2026-44321free5GC: SMF UPI POST /upi/v1/upNodesLinks exits the SMF process on overlapping UE pools (unauthenticated, reachable Fatalf)7.5
The record
- Peak rank
- #49 in Feb 2026
- Busiest month shown
- Feb 2026, 22 CVEs
- Months with a KEV entry
- 0 since Nov 2023
- Monthly snapshots
- 7 since 2023