top of page
perceptive_background_267k.jpg

An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS)…

Published:

27 augustus 2026 om 00:00:00

Alert date:

27 augustus 2026 om 23:07:34

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Critical Infrastructure, Emerging Technologies

CVE-2026-30050 is a Denial of Service vulnerability found in free5gc v4.1.0, an open-source 5G core network implementation. The flaw exists in the ModifyAMFEventSubscriptionProcedure function within the processor/event_exposure.go file. Attackers can exploit this vulnerability by sending a specially crafted PATCH request to trigger a DoS condition. The vulnerability was reported via the free5gc GitHub issue tracker. No authentication bypass or data exfiltration is described, but service availability is at risk. The affected component relates to AMF (Access and Mobility Management Function) event subscription handling, a critical part of 5G network signaling. This could impact telecommunications infrastructure relying on free5gc for 5G core services. A fix or patch status was not explicitly mentioned in the article.

Technical details

Mitigation steps:

Affected products:

free5gc v4.1.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page