Description
An issue in the NF Discovery endpoint of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted snssais query.
Published: 2026-08-27
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Assess Impact
AI Analysis

Impact

An issue exists in the NF Discovery endpoint of free5gc open‑source 5G core version 4.0.1 that allows an attacker to trigger a denial of service by submitting a specially crafted snssais query. The vulnerability is manifested when the endpoint processes this input and fails to handle it correctly, resulting in the target service becoming unresponsive or crashing. The primary impact is the loss of availability for the affected network function.

Affected Systems

The affected product is the free5gc open‑source 5G core implementation, specifically version 4.0.1. No other vendors or product variants are listed as impacted.

Risk and Exploitability

The CVSS score is 7.5, reflecting a high severity. The EPSS score is < 1%, indicating a very low probability of exploitation. Based on the description, it is inferred that an attacker with network access to the NF Discovery endpoint could trigger the denial‑of‑service, although the authentication level required is not specified. The attack vector is thus inferred to be remote. The vulnerability is not listed in CISA’s KEV catalog, indicating that no known exploit has been publicly reported.

Generated by OpenCVE AI on August 31, 2026 at 20:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict access to the NF Discovery endpoint so that only trusted internal networks can reach it
  • Apply the latest patch or upgrade to a fixed version of free5gc as released by the project maintainers
  • Enable logging and alerting for repeated malformed snssais queries to detect potential DoS attempts

Generated by OpenCVE AI on August 31, 2026 at 20:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Free5GC NF Discovery Denial of Service Vulnerability

Mon, 31 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Crafted snssais Query in free5gc NF Discovery Endpoint
Weaknesses CWE-400

Mon, 31 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via Crafted snssais Query in free5gc NF Discovery Endpoint
First Time appeared Free5gc
Free5gc free5gc
Weaknesses CWE-400
Vendors & Products Free5gc
Free5gc free5gc

Thu, 27 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description An issue in the NF Discovery endpoint of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted snssais query.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-31T16:19:47.260Z

Reserved: 2026-03-04T00:00:00.000Z

Link: CVE-2026-30063

cve-icon Vulnrichment

Updated: 2026-08-31T16:13:22.783Z

cve-icon NVD

Status : Deferred

Published: 2026-08-27T17:17:51.500

Modified: 2026-08-31T20:59:32.817

Link: CVE-2026-30063

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T20:45:04Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling