VulnSea

free5gc has 8 CVEs on record. Disclosure cadence is accelerating: 5 in the last 90 days against 2 in the 90 before. The busiest recent month was August 2026 with 3. The median CVSS is 7.5 (high), with 3 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-20 (3). Most affected products: github.com/free5gc/ausf (2), github.com/free5gc/free5gc (2), free5gc (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
5 prev 2

Products

  • github.com/free5gc/ausf 2
  • github.com/free5gc/free5gc 2
  • free5gc 1
  • github.com/free5gc/nef 1
  • github.com/free5gc/nrf 1
  • github.com/free5gc/udr 1
8
Total CVEs
3
Critical
0
CISA KEV
0
Exploited

free5gc vulnerabilities

CVEs affecting free5gc, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-47780Medium· 6.9PoC
1w ago

free5GC is an open-source implementation of the 5G core network

free5GC is an open-source implementation of the 5G core network. In 4.2.3 and earlier, HandleCreateEeSubscriptions and HandleQueryeesubscriptions in free5gc/udr internal/sbi/api_datarepository.go validate the ueId path value with a regul…

Twilightfree5gc · free5gcEPSS 0.40%via NVD
CVE-2026-55785Low· 3.7
3w ago

free5GC is an open-source implementation of the 5G core network

free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the AUSF component performs cryptographic authentication comparisons in internal/sbi/processor/ue_authentication.go with ordinary equality helpers. Auth5gAk…

Sunlitfree5gc · github.com/free5gc/ausfEPSS 0.28%via NVD
CVE-2026-55784High· 7.5
3w ago

free5GC is an open-source implementation of the 5G core network

free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores per-subscriber authentication state in a global sync.Map named AUSFContext.UePool in internal/context/context.go, ke…

Twilightfree5gc · github.com/free5gc/ausfEPSS 0.25%via NVD
CVE-2026-55068Critical
3w ago

free5GC is an open-source implementation of the 5G core network

free5GC is an open-source implementation of the 5G core network. In 4.2.2 and earlier, the NRF RegisterNFInstance handler at PUT /nnrf-nfm/v1/nf-instances/{nfInstanceID} accepts NF Profiles without enforcing UUID format, nfStatus enum va…

Midnightfree5gc · github.com/free5gc/free5gcEPSS 0.44%via NVD
CVE-2026-53551Medium
1mo ago

free5GC is an open-source implementation of the 5G core network

free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the free5GC AUSF (Authentication Server Function) does not validate the supiOrSuci field in UE authentication requests. Null bytes (\x00) and other control …

Sunlitfree5gc · github.com/free5gc/free5gcEPSS 0.55%via NVD
CVE-2026-44327Critical· 10.0
4mo ago

free5GC's NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handler

free5GC's NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handler

Midnightfree5gc · github.com/free5gc/nefEPSS 0.31%via OSV
CVE-2026-40246High· 7.5
5mo ago

free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions

free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions

Twilightfree5gc · github.com/free5gc/udrEPSS 0.38%via OSV
CVE-2025-66719Critical· 9.1
8mo ago

Free5gc NRF is vulnerable to scope validation bypass via maliciously crafted targetNF value

Free5gc NRF is vulnerable to scope validation bypass via maliciously crafted targetNF value

Midnightfree5gc · github.com/free5gc/nrfEPSS 0.35%via OSV
free5gc vulnerabilities (CVEs) · VulnSea