CVE-2026-26024General(free5gc / smf)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, SMF panics and terminates when processing a malformed PFCP SessionReportRequest on the PFCP (UDP/8805) interface. No known upstream fix is available, but some workarounds are available. ACL/firewall the PFCP interface so only trusted UPF IPs can reach SMF (reduce spoofing/abuse surface); drop/inspect malformed PFCP SessionReportRequest messages at the network edge where feasible, and/or add recover() around PFCP handler dispatch to avoid whole-process termination (mitigation only).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • smf

Threat summary

  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-02-24); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
smf

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-02-24: 2Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 102-2402-2702-2803-01
Signal classification2 categories
General
360.0%
Disclosure
240.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-242
Disclosure1General1
2026-02-271
Disclosure1
2026-02-281
General1
2026-03-011
General1
Full discourse5 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26024 Denial of Service in free5GC SMF via Malformed PFCP SessionReportRequest https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26024

    Post summary

    A DoS vulnerability (CVE-2026-26024) in free5GC SMF caused by malformed PFCP SessionReportRequest has been disclosed.

    0001051
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-26024 (CVSS:6.6, HIGH) is Analyzed. free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core..https://nvd.nist.gov/vuln/detail/CVE-2026-26024 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-26024 with its CVSS score but offers no further details on exploitation, patches, or PoC.

    0000020
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-26024 (CVSS:6.6, HIGH) is Analyzed. free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core..https://nvd.nist.gov/vuln/detail/CVE-2026-26024 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet notes CVE-2026-26024, gives its CVSS score and a link to the NVD entry, but offers no PoC, exploit, patch, or evidence of active exploitation.

    0000022
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-26024 (CVSS:6.6, HIGH) is Analyzed. free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core..https://nvd.nist.gov/vuln/detail/CVE-2026-26024 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet briefly announces the analysis of CVE‑2026‑26024, noting its CVSS score of 6.6 (HIGH) and that it impacts the free5GC SMF component of the open‑source 5G core stack.

    0000023
    173 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-26024 free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4… https://www.cve.org/CVERecord?id=CVE-2026-26024

    Post summary

    The text references CVE-2026-26024 for free5GC SMF but offers no additional details about the vulnerability, exploitation, or mitigation.

    00000152
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfree5gcsmf-go-

Explore more