CVE-2026-44328Disclosure(free5gc / free5gc)

LOWCVSS 8.2 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound OAuth2 middleware. On top of that, the DELETE /upi/v1/upNodesLinks/{upNodeRef} handler unconditionally dereferences upNode.UPF after the type-guarded async release, even though AN-typed nodes are constructed without a UPF object. As a result, a single unauthenticated DELETE /upi/v1/upNodesLinks/gNB1 request crashes the handler with a nil-pointer panic AND mutates the in-memory user-plane topology before panicking (the UpNodeDelete(upNodeRef) line runs first). This is an unauthenticated, state-mutating panic-DoS sink that an off-path network attacker can trigger by name against any AN entry. This vulnerability is fixed in 4.2.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306CWE-476CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • free5gc

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-09); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
free5gc

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-05-09: 2Mentions · 2026-06-17: 2Technical Details · 2026-05-09: 2Technical Details · 2026-06-17: 205-0906-17
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-092
Disclosure1General1
2026-06-172
Disclosure2
Full discourse4 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-44328 · v4.2.1 → 10.100.200.6 A critical authentication bypass in free5GC's Session Management Function (SMF) allows unauthenticated attackers to delete user-plane nodes and trigger nil-pointer panics via the /upi/v1/upNodesLinks endpoint.

    Post summary

    The text announces a critical authentication bypass in free5GC's SMF, detailing how unauthenticated attackers can delete nodes and cause nil-pointer panics via a specific endpoint.

    10000124
    289 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    A critical authentication bypass in free5GC's Session Management Function (SMF) allows unauthenticated attackers to delete user-plane nodes and trigger nil-pointer panics via the /upi/v1/upNodesLinks endpoint. The vulnerability (CVE-2026-44328 / GHSA-p9mg-74mg-cwwr)…

    Post summary

    The text discloses a critical authentication bypass in free5GC’s SMF (CVE‑2026‑44328), allowing unauthenticated attackers to delete user‑plane nodes and cause nil‑pointer crashes via the /upi/v1/upNodesLinks endpoint.

    10000118
    289 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 free5GC #SMF, Unauthenticated Process-Kill DoS, #CVE-2026-44328 (Medium) https://dailycve.com/free5gc-smf-unauthenticated-process-kill-dos-cve-2026-44328-medium/

    Post summary

    A new medium‑severity CVE (CVE‑2026‑44328) is announced for the free5GC SMF, allowing unauthenticated users to kill processes and cause a denial‑of‑service. No PoC, exploit, or patch information is included.

    0000043
    198 followersView on X
  • DailyCVE@dailycve
    General

    🔴 free5GC #SMF, Missing Authentication in UPI Route Group, #CVE-2026-44328 (High) https://dailycve.com/free5gc-smf-missing-authentication-in-upi-route-group-cve-2026-44328-high/

    Post summary

    The text announces a high‑severity vulnerability (CVE‑2026‑44328) in free5GC SMF involving missing authentication in the UPI Route Group, but provides no evidence of exploits, patches, or PoCs.

    0000039
    198 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfree5gcfree5gc---

Explore more