VendorsFree5GCsmfall versions
Vulnerabilities

Free5GC SMF

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2023-47346
Buffer Overflow vulnerability in free5gc 3.3.0, UPF 1.2.0, and SMF 1.2.0 allows attackers to cause a denial of service via crafted PFCP messages.
Published 2023-11-13 · Modified
7.5EPSS 0.008
CVE-2026-25501
free5GC SMF crash (nil pointer dereference) on PFCP SessionReportRequest when ReportType.DLDR is set but DownlinkDataReport IE is missing
Published 2026-02-24 · Analyzed
7.5EPSS 0.005
CVE-2026-26024
free5GC SMF crash (nil pointer dereference) on PFCP SessionReportRequest when ReportType.USAR=1 and UsageReport omits mandatory URRID sub-IE 
Published 2026-02-24 · Analyzed
7.5EPSS 0.005
CVE-2026-26025
free5GC SMF crash (nil pointer dereference) on PFCP SessionReportRequest when ReportType.USAR=1 and UsageReport omits mandatory URRID sub-IE 
Published 2026-02-24 · Analyzed
7.5EPSS 0.005
CVE-2025-69232
free5GC hasProtocol Compliance Violation in UPF Leading to SMF Service Disruption
Published 2026-02-23 · Analyzed
7.5EPSS 0.004