CVE-2026-26025Disclosure(free5gc / smf)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, SMF panics and terminates when processing a malformed PFCP SessionReportRequest on the PFCP (UDP/8805) interface. No known upstream fix is available, but some workarounds are available. ACL/firewall the PFCP interface so only trusted UPF IPs can reach SMF (reduce spoofing/abuse surface); drop/inspect malformed PFCP SessionReportRequest messages at the network edge where feasible, and/or add recover() around PFCP handler dispatch to avoid whole-process termination (mitigation only).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • smf

Threat summary

  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-02-24); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
smf

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-02-24: 2Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 102-2402-2702-2803-01
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-242
Disclosure1General1
2026-02-271
Disclosure1
2026-02-281
General1
2026-03-011
Disclosure1
Full discourse5 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26025 Denial of Service Vulnerability in free5GC SMF PFCP SessionReportRequest Handling https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26025

    Post summary

    A new DoS vulnerability (CVE-2026-26025) affecting free5GC SMF PFCP SessionReportRequest handling has been disclosed.

    0001061
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-26025 (CVSS:6.6, HIGH) is Analyzed. free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core..https://nvd.nist.gov/vuln/detail/CVE-2026-26025 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-26025 with a CVSS score of 6.6, indicating a high severity vulnerability in free5GC's SMF component, but provides no further details on exploitation or mitigation.

    0000019
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-26025 (CVSS:6.6, HIGH) is Analyzed. free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core..https://nvd.nist.gov/vuln/detail/CVE-2026-26025 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet simply cites CVE‑2026‑26025 with its CVSS score and links to the NVD page, without providing any details on exploitation, patches, or PoC.

    0000023
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-26025 (CVSS:6.6, HIGH) is Analyzed. free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core..https://nvd.nist.gov/vuln/detail/CVE-2026-26025 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-26025 is presented with its CVSS score and a link to the NIST database, but no exploit, patch, or technical details are disclosed.

    0000039
    173 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-26025 free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4… https://www.cve.org/CVERecord?id=CVE-2026-26025

    Post summary

    The text references CVE-2026-26025 in free5GC SMF but offers no additional details about the vulnerability, exploitation, or mitigation.

    00000151
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfree5gcsmf-go-

Explore more