{"schema_version":1,"title":"free5GC vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 42 vulnerabilities in free5GC: 1 in the last 7 days and 21 in the last 90 days, 7 of them critical and 0 exploited in the wild. The most recent, CVE-2026-94043, was published on 20 September 2026. 7 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/free5gc","json_url":"https://junglewise.ai/threats/vendors/free5gc.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/free5gc","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":27,"all_time":42,"critical":7,"exploited":0,"last_7_days":1,"last_30_days":4,"last_90_days":21,"last_365_days":42},"latest":[{"cve":"CVE-2026-94043","cvss":5.3,"epss":0.0057,"slug":"cve-2026-94043-a-vulnerability-was-determined-in-free5gc-up-to-4-2-3-this","title":"Free5GC race condition in GMM handler RanUe context access","severity":"medium","exploited":false,"published_at":"2026-09-20T19:17:12.78+00:00","url":"https://junglewise.ai/threats/cve-2026-94043-a-vulnerability-was-determined-in-free5gc-up-to-4-2-3-this"},{"cve":"CVE-2026-47780","cvss":4,"epss":0.0054,"slug":"cve-2026-47780-free5gc-udr-improper-input-validation-in-ee-subscription-handlers","title":"free5GC is an open-source implementation of the 5G core network. In 4.2.3 and earlier, HandleCreateEeSubscriptions and HandleQueryeesubscrip","severity":"medium","exploited":false,"published_at":"2026-09-15T15:17:15.843+00:00","url":"https://junglewise.ai/threats/cve-2026-47780-free5gc-udr-improper-input-validation-in-ee-subscription-handlers"},{"cve":"CVE-2026-75439","cvss":7.5,"epss":0.0076,"slug":"cve-2026-75439-free5gc-upf-nil-pointer-dereference-in-pfcp-session-report","title":"Free5GC UPF nil pointer dereference in PFCP Session Report","severity":"high","exploited":false,"published_at":"2026-09-04T21:17:25.583+00:00","url":"https://junglewise.ai/threats/cve-2026-75439-free5gc-upf-nil-pointer-dereference-in-pfcp-session-report"},{"cve":"CVE-2026-55068","cvss":4,"epss":0.0059,"slug":"cve-2026-55068-free5gc-nrf-input-validation-bypass-in-nf-profile-registration","title":"free5GC is an open-source implementation of the 5G core network. In 4.2.2 and earlier, the NRF RegisterNFInstance handler at PUT /nnrf-nfm/v","severity":"critical","exploited":false,"published_at":"2026-08-28T20:18:24.183+00:00","url":"https://junglewise.ai/threats/cve-2026-55068-free5gc-nrf-input-validation-bypass-in-nf-profile-registration"},{"cve":"CVE-2026-30073","cvss":7.5,"epss":0.0046,"slug":"cve-2026-30073-free5gc-nssf-nil-pointer-dereference-in","title":"free5gc NSSF nil pointer dereference in NssaiAvailabilitySubscriptionCreate","severity":"high","exploited":false,"published_at":"2026-08-27T17:17:52.443+00:00","url":"https://junglewise.ai/threats/cve-2026-30073-free5gc-nssf-nil-pointer-dereference-in"},{"cve":"CVE-2026-30072","cvss":7.5,"epss":0.0046,"slug":"cve-2026-30072-free5gc-chf-null-pointer-dereference-in-cdr-processing","title":"free5gc CHF NULL pointer dereference in CDR processing","severity":"high","exploited":false,"published_at":"2026-08-27T17:17:52.32+00:00","url":"https://junglewise.ai/threats/cve-2026-30072-free5gc-chf-null-pointer-dereference-in-cdr-processing"},{"cve":"CVE-2026-30071","cvss":7.5,"epss":0.0046,"slug":"cve-2026-30071-free5gc-rechargeput-denial-of-service-in-input-parsing","title":"free5gc RechargePut denial of service in input parsing","severity":"high","exploited":false,"published_at":"2026-08-27T17:17:52.207+00:00","url":"https://junglewise.ai/threats/cve-2026-30071-free5gc-rechargeput-denial-of-service-in-input-parsing"},{"cve":"CVE-2026-30070","cvss":7.5,"epss":0.0046,"slug":"cve-2026-30070-free5gc-udm-handlegetshareddata-denial-of-service","title":"free5GC UDM HandleGetSharedData denial of service","severity":"high","exploited":false,"published_at":"2026-08-27T17:17:52.09+00:00","url":"https://junglewise.ai/threats/cve-2026-30070-free5gc-udm-handlegetshareddata-denial-of-service"},{"cve":"CVE-2026-30069","cvss":7.5,"epss":0.0046,"slug":"cve-2026-30069-free5gc-null-pointer-dereference-in-udmc-registration-handler","title":"free5GC NULL pointer dereference in UDMC registration handler","severity":"high","exploited":false,"published_at":"2026-08-27T17:17:51.973+00:00","url":"https://junglewise.ai/threats/cve-2026-30069-free5gc-null-pointer-dereference-in-udmc-registration-handler"},{"cve":"CVE-2026-30068","cvss":7.5,"epss":0.0046,"slug":"cve-2026-30068-free5gc-udm-improper-input-validation-in-parameter-provisioning","title":"free5GC UDM improper input validation in parameter provisioning","severity":"high","exploited":false,"published_at":"2026-08-27T17:17:51.857+00:00","url":"https://junglewise.ai/threats/cve-2026-30068-free5gc-udm-improper-input-validation-in-parameter-provisioning"},{"cve":"CVE-2026-30067","cvss":7.5,"epss":0.0046,"slug":"cve-2026-30067-free5gc-nrf-discovery-denial-of-service-in","title":"free5gc NRF Discovery denial of service in complexQueryFilterSubprocess","severity":"high","exploited":false,"published_at":"2026-08-27T17:17:51.74+00:00","url":"https://junglewise.ai/threats/cve-2026-30067-free5gc-nrf-discovery-denial-of-service-in"},{"cve":"CVE-2026-30064","cvss":7.5,"epss":0.0046,"slug":"cve-2026-30064-free5gc-oauth2-token-endpoint-denial-of-service-via-unmatched","title":"free5gc OAuth2 token endpoint denial of service via unmatched form key","severity":"high","exploited":false,"published_at":"2026-08-27T17:17:51.613+00:00","url":"https://junglewise.ai/threats/cve-2026-30064-free5gc-oauth2-token-endpoint-denial-of-service-via-unmatched"},{"cve":"CVE-2026-30063","cvss":7.5,"epss":0.0046,"slug":"cve-2026-30063-free5gc-nf-discovery-endpoint-denial-of-service-via-malformed","title":"free5gc NF Discovery endpoint denial of service via malformed snssais parameter","severity":"high","exploited":false,"published_at":"2026-08-27T17:17:51.5+00:00","url":"https://junglewise.ai/threats/cve-2026-30063-free5gc-nf-discovery-endpoint-denial-of-service-via-malformed"},{"cve":"CVE-2026-30062","cvss":7.5,"epss":0.0046,"slug":"cve-2026-30062-free5gc-ngap-handler-denial-of-service-via-malformed-nas-pdu","title":"free5gc NGAP handler denial of service via malformed NAS PDU","severity":"high","exploited":false,"published_at":"2026-08-27T17:17:51.38+00:00","url":"https://junglewise.ai/threats/cve-2026-30062-free5gc-ngap-handler-denial-of-service-via-malformed-nas-pdu"},{"cve":"CVE-2026-30059","cvss":7.5,"epss":0.0046,"slug":"cve-2026-30059-free5gc-nas-decoder-denial-of-service-in-5gsid-validation","title":"free5gc NAS decoder denial of service in 5GSID validation","severity":"high","exploited":false,"published_at":"2026-08-27T17:17:51.14+00:00","url":"https://junglewise.ai/threats/cve-2026-30059-free5gc-nas-decoder-denial-of-service-in-5gsid-validation"},{"cve":"CVE-2026-30058","cvss":7.5,"epss":0.0046,"slug":"cve-2026-30058-free5gc-amf-denial-of-service-in-httpmodifysubscription","title":"free5gc AMF denial of service in HTTPModifySubscription","severity":"high","exploited":false,"published_at":"2026-08-27T17:17:51.02+00:00","url":"https://junglewise.ai/threats/cve-2026-30058-free5gc-amf-denial-of-service-in-httpmodifysubscription"},{"cve":"CVE-2026-30057","cvss":7.5,"epss":0.0046,"slug":"cve-2026-30057-free5gc-amf-createuecontext-denial-of-service-via-multipart","title":"free5gc AMF CreateUEContext denial of service via multipart deserialization","severity":"high","exploited":false,"published_at":"2026-08-27T17:17:50.897+00:00","url":"https://junglewise.ai/threats/cve-2026-30057-free5gc-amf-createuecontext-denial-of-service-via-multipart"},{"cve":"CVE-2026-30056","cvss":7.5,"epss":0.0046,"slug":"cve-2026-30056-free5gc-amf-ngap-dispatcher-null-pointer-dereference","title":"free5gc AMF NGAP Dispatcher NULL pointer dereference","severity":"high","exploited":false,"published_at":"2026-08-27T17:17:50.783+00:00","url":"https://junglewise.ai/threats/cve-2026-30056-free5gc-amf-ngap-dispatcher-null-pointer-dereference"},{"cve":"CVE-2026-30051","cvss":7.5,"epss":0.0046,"slug":"cve-2026-30051-free5gc-amf-denial-of-service-via-crafted-ue-context-request","title":"free5gc AMF denial of service via crafted UE context request","severity":"high","exploited":false,"published_at":"2026-08-27T17:17:50.663+00:00","url":"https://junglewise.ai/threats/cve-2026-30051-free5gc-amf-denial-of-service-via-crafted-ue-context-request"},{"cve":"CVE-2026-30050","cvss":7.5,"epss":0.0046,"slug":"cve-2026-30050-free5gc-modifyamfeventsubscriptionprocedure-denial-of-service-via","title":"free5gc ModifyAMFEventSubscriptionProcedure denial of service via negative array index","severity":"high","exploited":false,"published_at":"2026-08-27T17:17:50.537+00:00","url":"https://junglewise.ai/threats/cve-2026-30050-free5gc-modifyamfeventsubscriptionprocedure-denial-of-service-via"},{"cve":"CVE-2026-53551","cvss":4,"epss":0.0074,"slug":"cve-2026-53551-free5gc-ausf-improper-input-validation-in-supiorsuci-field","title":"free5gc AUSF improper input validation in supiOrSuci field","severity":"medium","exploited":false,"published_at":"2026-07-31T20:16:51.697+00:00","url":"https://junglewise.ai/threats/cve-2026-53551-free5gc-ausf-improper-input-validation-in-supiorsuci-field"},{"cve":"CVE-2026-44330","cvss":10,"epss":0.0043,"slug":"cve-2026-44330-free5gc-nef-authentication-bypass-in-nnef-pfdmanagement-api","title":"free5GC NEF authentication bypass in nnef-pfdmanagement API","severity":"critical","exploited":false,"published_at":"2026-05-27T17:16:38.713+00:00","url":"https://junglewise.ai/threats/cve-2026-44330-free5gc-nef-authentication-bypass-in-nnef-pfdmanagement-api"},{"cve":"CVE-2026-44329","cvss":10,"epss":0.0056,"slug":"cve-2026-44329-free5gc-smf-missing-authentication-in-upi-management-interface","title":"free5GC SMF missing authentication in UPI management interface","severity":"critical","exploited":false,"published_at":"2026-05-27T17:16:38.49+00:00","url":"https://junglewise.ai/threats/cve-2026-44329-free5gc-smf-missing-authentication-in-upi-management-interface"},{"cve":"CVE-2026-44328","cvss":8.2,"epss":0.0054,"slug":"cve-2026-44328-free5gc-smf-unauthenticated-dos-and-state-mutation-in-upi-handler","title":"free5GC SMF unauthenticated DoS and state mutation in UPI handler","severity":"high","exploited":false,"published_at":"2026-05-27T17:16:38.347+00:00","url":"https://junglewise.ai/threats/cve-2026-44328-free5gc-smf-unauthenticated-dos-and-state-mutation-in-upi-handler"},{"cve":"CVE-2026-44327","cvss":10,"epss":0.0053,"slug":"cve-2026-44327-free5gc-nef-missing-authentication-in-oam-route-group","title":"free5GC NEF missing authentication in OAM route group","severity":"critical","exploited":false,"published_at":"2026-05-27T17:16:38.203+00:00","url":"https://junglewise.ai/threats/cve-2026-44327-free5gc-nef-missing-authentication-in-oam-route-group"}],"vendor":{"hub":true,"name":"free5GC","slug":"free5gc","homepage":"https://free5gc.org/","description":"free5GC is an open-source project for the 5th generation mobile core network.","url":"https://junglewise.ai/threats/vendors/free5gc"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":1,"exploited":0,"vulnerabilities":17},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-44329","cvss":10,"epss":0.0056,"slug":"cve-2026-44329-free5gc-smf-missing-authentication-in-upi-management-interface","title":"free5GC SMF missing authentication in UPI management interface","severity":"critical","exploited":false,"published_at":"2026-05-27T17:16:38.49+00:00","url":"https://junglewise.ai/threats/cve-2026-44329-free5gc-smf-missing-authentication-in-upi-management-interface"},{"cve":"CVE-2026-44327","cvss":10,"epss":0.0053,"slug":"cve-2026-44327-free5gc-nef-missing-authentication-in-oam-route-group","title":"free5GC NEF missing authentication in OAM route group","severity":"critical","exploited":false,"published_at":"2026-05-27T17:16:38.203+00:00","url":"https://junglewise.ai/threats/cve-2026-44327-free5gc-nef-missing-authentication-in-oam-route-group"},{"cve":"CVE-2026-44330","cvss":10,"epss":0.0043,"slug":"cve-2026-44330-free5gc-nef-authentication-bypass-in-nnef-pfdmanagement-api","title":"free5GC NEF authentication bypass in nnef-pfdmanagement API","severity":"critical","exploited":false,"published_at":"2026-05-27T17:16:38.713+00:00","url":"https://junglewise.ai/threats/cve-2026-44330-free5gc-nef-authentication-bypass-in-nnef-pfdmanagement-api"},{"cve":"CVE-2026-44326","cvss":9.4,"epss":0.0053,"slug":"cve-2026-44326-free5gc-nef-missing-authentication-in-3gpp-traffic-influence-api","title":"free5GC NEF missing authentication in 3gpp-traffic-influence API","severity":"critical","exploited":false,"published_at":"2026-05-27T17:16:38.053+00:00","url":"https://junglewise.ai/threats/cve-2026-44326-free5gc-nef-missing-authentication-in-3gpp-traffic-influence-api"},{"cve":"CVE-2026-44315","cvss":9.4,"epss":0.0053,"slug":"cve-2026-44315-free5gc-nef-missing-authorization-in-3gpp-pfd-management-api","title":"free5GC NEF missing authorization in 3gpp-pfd-management API","severity":"critical","exploited":false,"published_at":"2026-05-27T17:16:36.43+00:00","url":"https://junglewise.ai/threats/cve-2026-44315-free5gc-nef-missing-authorization-in-3gpp-pfd-management-api"},{"cve":"CVE-2025-66719","cvss":9.1,"epss":0.0035,"slug":"cve-2025-66719-free5gc-nrf-scope-validation-bypass-in-access-token-generation","title":"Free5gc NRF scope validation bypass in access-token generation","severity":"critical","exploited":false,"published_at":"2026-01-23T18:31:28+00:00","url":"https://junglewise.ai/threats/cve-2025-66719-free5gc-nrf-scope-validation-bypass-in-access-token-generation"},{"cve":"CVE-2026-55068","cvss":4,"epss":0.0059,"slug":"cve-2026-55068-free5gc-nrf-input-validation-bypass-in-nf-profile-registration","title":"free5GC is an open-source implementation of the 5G core network. In 4.2.2 and earlier, the NRF RegisterNFInstance handler at PUT /nnrf-nfm/v","severity":"critical","exploited":false,"published_at":"2026-08-28T20:18:24.183+00:00","url":"https://junglewise.ai/threats/cve-2026-55068-free5gc-nrf-input-validation-bypass-in-nf-profile-registration"},{"cve":"CVE-2026-42083","cvss":8.2,"epss":0.0055,"slug":"cve-2026-42083-free5gc-pcf-missing-authorization-in-smpolicycontrol-and","title":"free5GC PCF missing authorization in SMPolicyControl and UEPolicyControl","severity":"high","exploited":false,"published_at":"2026-05-27T17:16:35.327+00:00","url":"https://junglewise.ai/threats/cve-2026-42083-free5gc-pcf-missing-authorization-in-smpolicycontrol-and"},{"cve":"CVE-2026-44328","cvss":8.2,"epss":0.0054,"slug":"cve-2026-44328-free5gc-smf-unauthenticated-dos-and-state-mutation-in-upi-handler","title":"free5GC SMF unauthenticated DoS and state mutation in UPI handler","severity":"high","exploited":false,"published_at":"2026-05-27T17:16:38.347+00:00","url":"https://junglewise.ai/threats/cve-2026-44328-free5gc-smf-unauthenticated-dos-and-state-mutation-in-upi-handler"},{"cve":"CVE-2026-75439","cvss":7.5,"epss":0.0076,"slug":"cve-2026-75439-free5gc-upf-nil-pointer-dereference-in-pfcp-session-report","title":"Free5GC UPF nil pointer dereference in PFCP Session Report","severity":"high","exploited":false,"published_at":"2026-09-04T21:17:25.583+00:00","url":"https://junglewise.ai/threats/cve-2026-75439-free5gc-upf-nil-pointer-dereference-in-pfcp-session-report"}],"generated_at":"2026-09-27T03:07:00.185062+00:00","technologies":[{"name":"free5GC","slug":"free5gc","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/free5gc"},{"name":"free5GC Nef","slug":"nef","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/nef"},{"name":"free5GC Udr","slug":"udr","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/udr"},{"name":"free5GC NRF","slug":"nrf","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/nrf"},{"name":"free5GC Pcf","slug":"pcf","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/pcf"},{"name":"free5GC SMF","slug":"smf","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/smf"},{"name":"free5GC Udm","slug":"udm","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/udm"}]}