PT-2026-45556 · Undefined · Undefined
Published
2026-06-01
·
Updated
2026-06-01
·
CVE-2026-37234
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
FlexRIC v2.0.0 allows a single SCTP connection to bind multiple xapp ids by sending multiple E42 SETUP REQUESTs. On disconnect, only the first registered xapp id's resources are cleaned up; subsequent xapp ids and their subscriptions remain as stale entries. A remote attacker can exploit this to leak subscription state in the iApp, potentially causing resource exhaustion or state corruption over time.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined