CVE-2026-1974Disclosure(free5gc / free5gc)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in Free5GC up to 4.1.0. This affects the function ResolveNodeIdToIp of the file internal/sbi/processor/datapath.go of the component SMF. The manipulation leads to denial of service. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. It is recommended to apply a patch to fix this issue.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-404

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • free5gc

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
free5gc

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-06: 2Technical Details · 2026-02-06: 202-06
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1974 Denial of Service Vulnerability in Free5GC SMF Component Up to 4.1... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1974 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The post announces CVE‑2026‑1974, a denial‑of‑service flaw in the Free5GC SMF component (up to v4.1), with details available via a Vulmon link, but it does not provide a PoC, exploit code, or patch information.

    0000064
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1974 A vulnerability was identified in Free5GC up to 4.1.0. This affects the function ResolveNodeIdToIp of the file internal/sbi/processor/datapath.go of the component SMF. … https://www.cve.org/CVERecord?id=CVE-2026-1974

    Post summary

    The post announces CVE-2026-1974 in Free5GC SMF’s ResolveNodeIdToIp function, providing technical details but no PoC, exploitation evidence, or patch information.

    00000247
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfree5gcfree5gc---

Explore more