Description
An issue in free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) when parsing crafted SUCI data during UE registration.
Published: 2026-08-27
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

free5gc v4.0.1 contains an error that allows a denial of service when malicious SUCI data is processed during user equipment registration. The flaw arises from an improper handling of SUCI fields, consistent with CWE‑770, leading to either crashes or resource exhaustion in the parsing subsystem. A successful exploitation would stop the registration process for the network, potentially making the core unavailable to legitimate subscribers.

Affected Systems

The vulnerability is limited to the free5gc open‑source 5G core stack, specifically version 4.0.1. No other versions or product variants are known to be affected based on the current advisory.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, while the EPSS score of less than 1 % signals a very low observed probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, and no public exploits are available. Based on the description, it is inferred that the attack would be carried out remotely by injecting crafted SUCI data into the UE registration flow, but the lack of concrete proof means the attack path remains hypothetical.

Generated by OpenCVE AI on August 31, 2026 at 21:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade free5gc to the latest stable release where the SUCI parsing issue has been resolved.
  • If a quick upgrade is not possible, deploy network‑level rate limiting or traffic shaping on UE registration messages to reduce the impact of repeated malformed SUCI packets.
  • Enable detailed logging of SUCI parsing failures and configure an alerting rule to flag repeated blocks for manual investigation.

Generated by OpenCVE AI on August 31, 2026 at 21:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via Malformed SUCI Data in free5gc v4.0.1

Mon, 31 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via Crafted SUCI Data in free5gc v4.0.1
Weaknesses CWE-749

Mon, 31 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via Crafted SUCI Data in free5gc v4.0.1
First Time appeared Free5gc
Free5gc free5gc
Weaknesses CWE-749
Vendors & Products Free5gc
Free5gc free5gc

Thu, 27 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description An issue in free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) when parsing crafted SUCI data during UE registration.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-31T16:19:47.419Z

Reserved: 2026-03-04T00:00:00.000Z

Link: CVE-2026-30060

cve-icon Vulnrichment

Updated: 2026-08-31T16:13:24.857Z

cve-icon NVD

Status : Deferred

Published: 2026-08-27T17:17:51.260

Modified: 2026-08-31T20:59:32.817

Link: CVE-2026-30060

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T22:00:06Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling