Description
Improper Input Validation in the HTTPModifySubscription handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published: 2026-08-27
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Update Software
AI Analysis

Impact

An attacker can cause a denial of service by sending a crafted HTTP request to the HTTPModifySubscription handler in free5gc version 4.0.1. The improper input validation allows the server to become unresponsive or crash, disrupting control plane services and potentially affecting all connected subscribers. The vulnerability does not compromise confidentiality or integrity, but loss of availability can have serious operational impact for mobile network operators.

Affected Systems

The vulnerability is present only in the free5gc implementation of 5G core network functions, specifically version 4.0.1. No other vendor or product is listed.

Risk and Exploitability

The CVSS score is 7.5, indicating a high severity, while the EPSS score is <1%, suggesting a very low probability of exploitation as of the current data. The weakness remains exploitable with any HTTP request to the affected endpoint and does not require authentication. The vulnerability is not listed in the CISA KEV catalog. Without an official patch, the risk remains unless mitigated by updating or hardening the service.

Generated by OpenCVE AI on August 31, 2026 at 18:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the newest free5gc release that contains the fix for the HTTPModifySubscription input validation bug.
  • If an upgrade cannot be performed immediately, limit access to the HTTPModifySubscription endpoint to trusted networks or devices, and apply rate limiting to reduce the chance of a successful DoS attempt.
  • Add explicit input validation in your deployment to reject malformed or oversized requests before they reach the free5gc core functions.

Generated by OpenCVE AI on August 31, 2026 at 18:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via Improper Input Validation in free5gc HTTPModifySubscription

Mon, 31 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via Improper Input Validation in free5gc HTTPModifySubscription
First Time appeared Free5gc
Free5gc free5gc
Weaknesses CWE-20
Vendors & Products Free5gc
Free5gc free5gc

Thu, 27 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description Improper Input Validation in the HTTPModifySubscription handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-31T16:13:59.802Z

Reserved: 2026-03-04T00:00:00.000Z

Link: CVE-2026-30058

cve-icon Vulnrichment

Updated: 2026-08-31T16:13:52.143Z

cve-icon NVD

Status : Deferred

Published: 2026-08-27T17:17:51.020

Modified: 2026-08-31T20:59:32.817

Link: CVE-2026-30058

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T19:00:04Z

Weaknesses
  • CWE-20

    Improper Input Validation