PT-2026-66852 · Free5Gc · Free5Gc
CVE-2026-53551
·
Published
2026-07-31
·
Updated
2026-07-31
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
free5GC versions prior to 1.4.5
Description
The AUSF (Authentication Server Function) fails to validate the
supiOrSuci field in UE authentication requests. Null bytes (x00) and other control characters are passed through JSON parsing and forwarded to the UDM in an unescaped URL path. This causes the net/url.Parse() function to fail, resulting in an HTTP 500 System failure and the leakage of internal stack traces. An unauthenticated attacker can exploit this at the POST /nausf-auth/v1/ue-authentications endpoint to cause a denial of service for all subscribers attempting authentication through the affected AUSF.Recommendations
Update to version 1.4.5.
As a temporary workaround, restrict access to the
POST /nausf-auth/v1/ue-authentications endpoint to minimize the risk of exploitation.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Free5Gc