top of page
perceptive_background_267k.jpg

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NRF root SBI endpoint POST /oauth2/token contains a parser-level type…

Published:

26 mei 2026 om 22:00:00

Alert date:

27 mei 2026 om 18:07:10

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Mobile & IoT, Web Technologies

free5GC, an open-source 5G core network implementation, contains a type-confusion vulnerability in its NRF OAuth2 token endpoint prior to version 4.2.2. The vulnerability exists in the POST /oauth2/token endpoint handler which incorrectly parses form data, treating most fields as PlmnId objects. This causes type mismatches that trigger panics when incompatible types are assigned. The endpoint can be remotely exploited through unauthenticated form-encoded requests, causing HTTP 500 errors and repeated denial of service. The vulnerability affects the NFs/nrf/internal/sbi/api_accesstoken.go file and has been fixed in version 4.2.2.

Technical details

Mitigation steps:

Affected products:

free5GC

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page