Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.2 HIGH
CVE-2026-44328 — free5GC: SMF UPI DELETE /upi/v1/upNodesLinks/{ref} panics on AN-node deletion via nil UPF…

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound OAuth2 middleware. On top of that, the DELETE /upi…

free5gc | Remote | Denial of Service
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
10.0 CRITICAL
CVE-2026-44327 — free5GC: NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM han…

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route group without inbound OAuth2/bearer-token authorization. A network attacker wh…

free5gc | Remote | Authorization
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
9.4 CRITICAL
CVE-2026-44326 — free5GC: NEF 3gpp-traffic-influence API is unauthenticated; missing or forged bearer toke…

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-traffic-influence API without inbound OAuth2/bearer-token authorization. A network attac…

free5gc | Remote | Authentication
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
7.5 HIGH
CVE-2026-44325 — free5GC: NRF POST /oauth2/token structured-form parser type-confusion panic family (Refle…

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NRF root SBI endpoint POST /oauth2/token contains a parser-level type-confusion bug family. The handler in N…

free5gc | Remote | Memory Corruption
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
6.5 MEDIUM
CVE-2026-44324 — free5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interfac…

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's UDR nudr-dr DELETE /subscription-data/{ueId}/{servingPlmnId}/ee-subscriptions/{subsId}/amf-subscriptions han…

free5gc | Remote | Denial of Service
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
6.5 MEDIUM
CVE-2026-44323 — free5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exis…

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's UDR nudr-dr DELETE /subscription-data/{ueId}/{servingPlmnId}/ee-subscriptions/{subsId}/amf-subscriptions han…

free5gc | Remote | Information Disclosure
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
7.5 HIGH
CVE-2026-44322 — free5GC: NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR access failure …

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF PATCH /3gpp-pfd-management/v1/{afId}/transactions/{transId}/applications/{appId} handler panics with a n…

free5gc | Remote | Information Disclosure
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
7.5 HIGH
CVE-2026-44321 — free5GC: SMF UPI POST /upi/v1/upNodesLinks exits the SMF process on overlapping UE pools …

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound OAuth2 middleware. The POST /upi/v1/upNodesLinks c…

free5gc | Remote | Denial of Service
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
7.3 HIGH
CVE-2026-44320 — free5GC: NEF nnef-callback route group is unauthenticated; forged callback requests are a…

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-callback route group without inbound OAuth2/bearer-token authorization. A forged or arbi…

free5gc | Remote | Authentication
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
7.5 HIGH
CVE-2026-44319 — free5GC: NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-cont…

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF terminates the entire process when a stored PFD-subscription notifyUri cannot be reached. In PfdChangeNo…

free5gc | Remote | Denial of Service
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
6.5 MEDIUM
CVE-2026-44318 — free5GC: BSF concurrent PUT /nbsf-management/v1/subscriptions/{subId} crashes the BSF pro…

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's BSF PUT /nbsf-management/v1/subscriptions/{subId} handler has an unsynchronized write on the global Subscrip…

free5gc | Remote | Race Condition
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
6.5 MEDIUM
CVE-2026-44317 — free5GC: PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missin…

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's PCF POST /npcf-policyauthorization/v1/app-sessions handler panics on a single authenticated request whose as…

free5gc | Remote | Memory Corruption
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
7.5 HIGH
CVE-2026-44316 — free5GC: PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 …

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's PCF POST /npcf-smpolicycontrol/v1/sm-policies handler (HandleCreateSmPolicyRequest) panics with a nil-pointe…

free5gc | Remote | Denial of Service
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
9.4 CRITICAL
CVE-2026-44315 — free5GC: NEF 3gpp-pfd-management API is unauthenticated; forged bearer tokens can create,…

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-pfd-management API without inbound OAuth2/bearer-token authorization. A network attacker…

free5gc | Remote | Authentication
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
8.1 HIGH
CVE-2026-42790 — nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verific…

Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verific…

erlang\/otp | Remote
May 27, 2026 Jun 02, 2026
May 27, 2026
Jun 02, 2026
7.7 HIGH
CVE-2026-42459 — free5GC: Improper Input Validation and Generation of Error Message Containing Sensitive I…

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the free5GC UDM component fails to validate the supi path parameter in six GET handlers of the nudm-sdm (Subscriber Da…

free5gc | Remote | Injection
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
8.2 HIGH
CVE-2026-42083 — free5GC: PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticate…

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers and dis…

free5gc | Remote | Authentication
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
5.4 MEDIUM
CVE-2026-42082 — free5GC: Missing Concurrent NAS SMC Validation During NGAP Handover

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not enforce the concurrent security procedure rules defined in 3GPP TS 33.501 §6.9.5.1. The AM…

free5gc | Remote | Authentication
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
7.1 HIGH
CVE-2026-42081 — free5GC: UE Security Capability bypass on NGAP PathSwitchRequest

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against it…

free5gc | Denial of Service
May 27, 2026 May 29, 2026
May 27, 2026
May 29, 2026
7.8 HIGH
CVE-2026-38945 — Raynet Rvia Command Injection Vulnerability

Command injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary code via a crafted path that matches the improperly terminated search criteria of …

| Injection
May 27, 2026 Jun 01, 2026
May 27, 2026
Jun 01, 2026
Showing 20 of 7097 Results