CVE-2026-1682Disclosure(free5gc / free5gc)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in Free5GC SMF up to 4.1.0. Affected is the function HandlePfcpAssociationReleaseRequest of the file internal/pfcp/handler/handler.go of the component PFCP UDP Endpoint. Executing a manipulation can lead to null pointer dereference. The attack may be launched remotely. The exploit has been published and may be used. A patch should be applied to remediate this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-404CWE-476

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • free5gc

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
free5gc

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-01-30: 2Technical Details · 2026-01-30: 201-30
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-1682 Null Pointer Dereference Exploit in Free5GC SMF PFCP UDP Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1682

    Post summary

    This brief entry notes a null pointer dereference vulnerability in Free5GC’s SMF PFCP UDP Endpoint with no additional details on PoC, exploitation, patch, or active use.

    0000068
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1682 A flaw has been found in Free5GC SMF up to 4.1.0. Affected is the function HandlePfcpAssociationReleaseRequest of the file internal/pfcp/handler/handler.go of the compo… https://www.cve.org/CVERecord?id=CVE-2026-1682

    Post summary

    A flaw was identified in Free5GC SMF up to version 4.1.0, specifically affecting the HandlePfcpAssociationReleaseRequest function; while technical details are provided, no exploit, PoC, patch, or active exploitation is mentioned.

    00000200
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfree5gcfree5gc---

Explore more