PT-2026-21563 · Free5Gc · Smf+1

Published

2026-02-23

·

Updated

2026-02-28

·

CVE-2025-69232

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions free5GC go-upf versions up to and including 1.2.6 free5gc smf versions up to and including 1.4.0
Description The software contains an Improper Input Validation and Protocol Compliance issue that can lead to Denial of Service. Remote attackers can disrupt core network functionality by sending a malformed PFCP Association Setup Request to the UPF. The UPF incorrectly accepts this request, entering an inconsistent state that causes legitimate requests to trigger SMF reconnection loops and service degradation. All deployments of free5GC using the UPF and SMF components may be affected. PFCP stands for Protocol for Control Plane Communication, a protocol used for communication between the SMF and UPF.
Recommendations Apply the official patch once it is released.

Exploit

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-69232
GHSA-8M42-QW58-8362

Affected Products

Go-Upf
Smf