CVE-2026-1683 is a denial-of-service vulnerability affecting Free5GC SMF versions up to 4.1.0, specifically within the HandlePfcpSessionReportRequest function of the PFCP component. With a CVSS score of 7.5 (HIGH), this vulnerability can be exploited remotely without authentication, leading to service disruption. While public exploit details exist, there is no evidence of active exploitation, and it currently lacks significant community discussion or media coverage. Organizations using affected Free5GC versions are advised to apply the recommended patch to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.1.0CPE matchmatch criteria | cpe:2.3:a:free5gc:free5gc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.