free5gc has 8 CVEs on record. Disclosure cadence is accelerating: 5 in the last 90 days against 2 in the 90 before. The busiest recent month was August 2026 with 3. The median CVSS is 7.5 (high), with 3 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-20 (3). Most affected products: github.com/free5gc/ausf (2), github.com/free5gc/free5gc (2), free5gc (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 5 prev 2
Products
- github.com/free5gc/ausf 2
- github.com/free5gc/free5gc 2
- free5gc 1
- github.com/free5gc/nef 1
- github.com/free5gc/nrf 1
- github.com/free5gc/udr 1
Worst active — by depth score
CVE-2026-44327Critical· 10.0free5GC's NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handler55CVE-2026-55068Criticalfree5GC is an open-source implementation of the 5G core network52CVE-2026-47780Medium· 6.9free5GC is an open-source implementation of the 5G core network50CVE-2025-66719Critical· 9.1Free5gc NRF is vulnerable to scope validation bypass via maliciously crafted targetNF value50CVE-2026-55784High· 7.5free5GC is an open-source implementation of the 5G core network41
free5gc vulnerabilities
CVEs affecting free5gc, newest first. Open any entry for full detail, references, and exploit status.
8 CVEsRSS
CVE-2026-47780Medium· 6.9PoCfree5GC is an open-source implementation of the 5G core network
free5GC is an open-source implementation of the 5G core network. In 4.2.3 and earlier, HandleCreateEeSubscriptions and HandleQueryeesubscriptions in free5gc/udr internal/sbi/api_datarepository.go validate the ueId path value with a regul…
CVE-2026-55785Low· 3.7free5GC is an open-source implementation of the 5G core network
free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the AUSF component performs cryptographic authentication comparisons in internal/sbi/processor/ue_authentication.go with ordinary equality helpers. Auth5gAk…
CVE-2026-55784High· 7.5free5GC is an open-source implementation of the 5G core network
free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores per-subscriber authentication state in a global sync.Map named AUSFContext.UePool in internal/context/context.go, ke…
CVE-2026-55068Criticalfree5GC is an open-source implementation of the 5G core network
free5GC is an open-source implementation of the 5G core network. In 4.2.2 and earlier, the NRF RegisterNFInstance handler at PUT /nnrf-nfm/v1/nf-instances/{nfInstanceID} accepts NF Profiles without enforcing UUID format, nfStatus enum va…
CVE-2026-53551Mediumfree5GC is an open-source implementation of the 5G core network
free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the free5GC AUSF (Authentication Server Function) does not validate the supiOrSuci field in UE authentication requests. Null bytes (\x00) and other control …
CVE-2026-44327Critical· 10.0free5GC's NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handler
free5GC's NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handler
CVE-2026-40246High· 7.5free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions
free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions
CVE-2025-66719Critical· 9.1Free5gc NRF is vulnerable to scope validation bypass via maliciously crafted targetNF value
Free5gc NRF is vulnerable to scope validation bypass via maliciously crafted targetNF value