


Perceptive Security
SOC/SIEM Consultancy

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NRF root SBI endpoint POST /oauth2/token contains a parser-level type…
Published:
26 mei 2026 om 22:00:00
Alert date:
27 mei 2026 om 18:07:10
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT, Web Technologies
free5GC, an open-source 5G core network implementation, contains a type-confusion vulnerability in its NRF OAuth2 token endpoint prior to version 4.2.2. The vulnerability exists in the POST /oauth2/token endpoint handler which incorrectly parses form data, treating most fields as PlmnId objects. This causes type mismatches that trigger panics when incompatible types are assigned. The endpoint can be remotely exploited through unauthenticated form-encoded requests, causing HTTP 500 errors and repeated denial of service. The vulnerability affects the NFs/nrf/internal/sbi/api_accesstoken.go file and has been fixed in version 4.2.2.
Technical details
Mitigation steps:
Affected products:
free5GC
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44325
https://github.com/free5gc/free5gc/issues/918
https://github.com/free5gc/free5gc/security/advisories/GHSA-f8qv-7x5w-qr48
https://github.com/free5gc/nrf/commit/f7bc77daa7425506af7569f2e61c2a210f5a0423
https://github.com/free5gc/nrf/pull/83
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
