CVE-2026-33063Disclosure(free5gc / free5gc)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch free5gc free5gc systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

free5GC is an open source 5G core network. free5GC AUSF prior to version 1.4.2 has is an Improper Null Check vulnerability leading to Denial of Service. All deployments of free5GC v4.0.1 using the AUSF UE authentication service (`/nausf-auth/v1/ue-authentications` endpoint) are affected. A remote attacker can cause the AUSF service to panic and crash by sending a crafted UE authentication request that triggers a nil interface conversion in the `GetSupiFromSuciSupiMap` function. This results in complete denial of service for the AUSF authentication service. The `GetSupiFromSuciSupiMap` function attempts to perform an interface conversion from `interface{}` to `*context.SuciSupiMap` without checking if the underlying value is nil. When `SuciSupiMap` is nil, the code panics with "interface conversion: interface {} is nil, not *context.SuciSupiMap". free5GC AUSF version 1.4.2 patches the issue. There is no direct workaround at the application level. The recommendation is to apply the provided patch or restrict access to the AUSF API to trusted sources only.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • free5gc

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-20); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
free5gc

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-20: 2Mentions · 2026-03-25: 1Mentions · 2026-08-29: 1Patch / Workaround · 2026-03-25: 1Technical Details · 2026-03-20: 2Technical Details · 2026-03-25: 1Technical Details · 2026-08-29: 103-2003-2508-29
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-202
Disclosure2
2026-03-251
Patch1
2026-08-291
Disclosure1
Full discourse4 posts
  • DailyCVE@dailycve
    Disclosure

    🟠 free5GC AUSF, Timing Side Channel, #CVE-2026-33063 (Medium) -DC-Aug2026-2045 https://dailycve.com/free5gc-ausf-timing-side-channel-cve-2026-33063-medium-dc-aug2026-2045/

    Post summary

    The post announces a Medium‑severity timing side‑channel vulnerability (CVE‑2026‑33063) in free5GC AUSF and links to a dailycve report page, but offers no proof of concept, exploit details, or patch information.

    0000041
    233 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A panic vulnerability (CVE-2026-33063) in `free5GC AUSF` can lead to a denial of service during UE authentication due to nil interface conversion. Admins should monitor for patches. #free5GC #DoS #infosec https://www.pulsepatch.io/posts/cve-2026-33063-free5gc-ausf-authentication-panic

    Post summary

    The post announces a denial‑of‑service CVE in free5GC AUSF, provides quick technical detail, and urges admins to keep an eye out for patches.

    0000067
    2 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33063 Denial of Service Vulnerability in free5GC AUSF Prior to Version 1.4.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33063

    Post summary

    A new CVE (CVE‑2026‑33063) has been disclosed, describing a denial‑of‑service flaw in free5GC AUSF prior to version 1.4.2; the text links to vulnerability details but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000035
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33063 free5GC is an open source 5G core network. free5GC AUSF prior to version 1.4.2 has is an Improper Null Check vulnerability leading to Denial of Service. All deploymen… https://www.cve.org/CVERecord?id=CVE-2026-33063

    Post summary

    The post identifies CVE-2026-33063 as an Improper Null Check vulnerability in free5GC's AUSF component that causes denial of service, but no PoC, exploit, active exploitation, or patch is detailed.

    0000044
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfree5gcfree5gc---

Explore more