Impact
The flaw resides in the NssaiAvailabilitySubscriptionCreate component of free5gc, a 5G core network open source project. An attacker can send a specially crafted HTTP POST request that causes the service to exhaust resources or crash, resulting in a denial of service. The weakness seems to relate to inadequate validation of user‑supplied input, leading to unbounded consumption or process termination.
Affected Systems
The vulnerability has been confirmed in free5gc version 4.0.1. No other affected versions are listed; users of the same component in later releases may remain at risk until a patch is applied.
Risk and Exploitability
Because the DoS payload is delivered via an HTTP POST to the control plane, the attack requires network access to the free5gc control interface and does not provide code execution or information disclosure. The CVSS score is 7.5, and the EPSS score is < 1%; the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation at this time. Nevertheless, a successful DoS could disrupt 5G services and impact availability for users attached to the network, so the risk warrants prompt attention.
OpenCVE Enrichment