Vulnerability index

Browse CVEs

81 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Free5gc HIGH 7.5
CVE-2026-1683

A vulnerability has been found in Free5GC SMF up to 4.1.0. Affected by this vulnerability is the function HandlePfcpSessionReportRequest of the file …

Fix: after 4.1.0
Fix from $1,950 2026-01-30
Pcf HIGH 7.5
CVE-2025-66720

Null pointer dereference in free5gc pcf 1.4.0 in file internal/sbi/processor/ampolicy.go in function HandleDeletePoliciesPolAssoId.

Patch available
Fix from $1,950 2026-01-23
Nrf CRITICAL 9.1
CVE-2025-66719

An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck() function in file internal/…

Patch available
Fix from $2,300 2026-01-23
Free5gc HIGH 7.5
CVE-2025-65561

An issue was discovered in function LocalNode.Sess in free5GC 4.1.0 allowing attackers to cause a denial of service or other unspecified impacts via …

Patch available
Fix from $1,950 2025-12-18
Free5gc HIGH 7.5
CVE-2025-65562

The free5GC UPF suffers from a lack of bounds checking on the SEID when processing PFCP Session Deletion Requests. An unauthenticated remote attacker…

No fix yet
Fix from $1,950 2025-12-18
Free5gc HIGH 7.5
CVE-2025-60638

An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Nnssf_NSSAIAva…

No fix yet
Fix from $1,950 2025-11-24
Free5gc MEDIUM 6.5
CVE-2025-60633

An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via the Nudm_SubscriberDataManagement API.

No fix yet
Fix from $1,600 2025-11-24
Free5gc MEDIUM 6.5
CVE-2025-60632

An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Npcf_BDTPolicy…

Mitigation only
Fix from $1,600 2025-11-24
Free5gc HIGH 7.5
CVE-2025-63679

free5gc v4.1.0 and before is vulnerable to Buffer Overflow. When AMF receives an UplinkRANConfigurationTransfer NGAP message from a gNB, the AMF proc…

Fix: after 4.1.0
Fix from $1,950 2025-11-12
Free5gc HIGH 7.5
CVE-2025-56394

Free5gc 4.0.1 is vulnerable to Buffer Overflow. The AMF incorrectly validates the 5GS mobile identity, resulting in slice reference overflow.

Patch available
Fix from $1,950 2025-09-23
Free5gc MEDIUM 5.4
CVE-2025-29632

Buffer Overflow vulnerability in Free5gc v.4.0.0 allows a remote attacker to cause a denial of service via the AMF, NGAP, security.go, handler_genera…

No fix yet
Fix from $1,600 2025-05-29
Free5gc HIGH 7.5
CVE-2023-49391

An issue was discovered in free5GC version 3.3.0, allows remote attackers to execute arbitrary code and cause a denial of service (DoS) on AMF compon…

No fix yet
Fix from $1,950 2023-12-22
Free5gc MEDIUM 5.5
CVE-2023-47025

An issue in Free5gc v.3.3.0 allows a local attacker to cause a denial of service via the free5gc-compose component.

No fix yet
Fix from $1,600 2023-11-16
Free5gc HIGH 7.5
CVE-2023-47345

Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP message with malformed PFCP Heartbeat m…

No fix yet
Fix from $1,950 2023-11-15
Free5gc HIGH 7.5
CVE-2023-47347

Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP messages whose Sequence Number is mutat…

No fix yet
Fix from $1,950 2023-11-15
Free5gc HIGH 7.5
CVE-2023-47346

Buffer Overflow vulnerability in free5gc 3.3.0, UPF 1.2.0, and SMF 1.2.0 allows attackers to cause a denial of service via crafted PFCP messages.

No fix yet
Fix from $1,950 2023-11-13
Udm HIGH 7.5
CVE-2023-46324

pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via …

Fix: 1.2.0+
Fix from $1,950 2023-10-23
Free5gc CRITICAL 9.8
CVE-2023-4659

Cross-Site Request Forgery vulnerability, whose exploitation could allow an attacker to perform different actions on the platform as an administrator…

Mitigation only
Fix from $2,300 2023-10-02
Free5gc HIGH 7.5
CVE-2022-38871

In Free5gc v3.0.5, the AMF breaks due to malformed NAS messages.

No fix yet
Fix from $1,950 2022-11-18
Free5gc HIGH 7.5
CVE-2022-38870

Free5gc v3.2.1 is vulnerable to Information disclosure.

No fix yet
Fix from $1,950 2022-10-25
Free5gc MEDIUM 5.5
CVE-2022-43677

In free5GC 3.2.1, a malformed NGAP message can crash the AMF and NGAP decoders via an index-out-of-range panic in aper.GetBitString.

No fix yet
Fix from $1,600 2022-10-24