CVE-2026-1684Disclosure(free5gc / free5gc)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in Free5GC SMF up to 4.1.0. Affected by this issue is the function HandleReports of the file /internal/context/pfcp_reports.go of the component PFCP UDP Endpoint. The manipulation results in denial of service. The attack can be executed remotely. It is advisable to implement a patch to correct this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-404

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • free5gc

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
free5gc

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-01-30: 2Technical Details · 2026-01-30: 101-30
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1684 Free5GC SMF Remote Denial of Service Vulnerability in PFCP UDP Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1684

    Post summary

    CVE‑2026‑1684 is a newly disclosed remote denial‑of‑service flaw targeting the PFCP UDP endpoint of Free5GC SMF.

    0000054
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1684 A vulnerability was found in Free5GC SMF up to 4.1.0. Affected by this issue is the function HandleReports of the file /internal/context/pfcp_reports.go of the componen… https://www.cve.org/CVERecord?id=CVE-2026-1684

    Post summary

    The message is a concise disclosure of CVE-2026-1684, noting the affected component and linking to the official CVE record, with no additional technical or exploit information.

    00000207
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfree5gcfree5gc---

Explore more