CVE-2026-5360 describes a type confusion vulnerability (CWE-843) in an unknown function of the 'aper' component within Free5GC version 4.2.0. This issue can be exploited remotely with high attack complexity, potentially leading to a low impact on availability, as indicated by its CVSS score of 3.7 (LOW). While not currently on CISA's KEV list or actively exploited, public exploit disclosure suggests the potential for future use, though common exploit frameworks do not yet contain modules. Community discussion is minimal, and a patch (26205eb01705754b7b902ad6c4b613c96c881e29) is available, with applying it considered best practice for mitigation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.2.0CPE matchmatch criteria | cpe:2.3:a:free5gc:free5gc:4.2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.