Free5gc is an open-source 5G core network implementation that, despite a narrow product portfolio, occupies a critical position in next-generation mobile infrastructure deployments and testing environments. The vendor's vulnerability footprint concentrates across its core service modules—including the Unified Data Management, Session Management Function, User Data Repository, and Policy Control Function components—and reflects the complexity inherent to distributed telecom protocol implementations and state management. The recurring weakness classes center on NULL-pointer dereferences, input-validation oversights, improper resource cleanup, authorization gaps, and sensitive-information leakage in error handling, which are characteristic of network-protocol parsers and service-to-service authentication boundaries in large-scale systems. Defenders operating 5G core infrastructure should monitor this vendor's releases closely and prioritize updates in internet-facing or untrusted-network deployments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Free5gc over time
Signals from CVEs in this vendor scope (82 CVEs).
82 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-44327CRITICAL free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route group without inbound OAuth2/bearer-token authorization. A | May 27, 2026 | 10.0 | 36 | NO | NO |
CVE-2026-44329CRITICAL free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without OAuth2/bearer-token authorization middl | May 27, 2026 | 10.0 | 35 | NO | NO |
CVE-2022-38870HIGH Free5gc v3.2.1 is vulnerable to Information disclosure. | Oct 25, 2022 | 7.5 | 35 | NO | YES |
CVE-2026-44326CRITICAL free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-traffic-influence API without inbound OAuth2/bearer-token authorizati | May 27, 2026 | 9.4 | 34 | NO | NO |
CVE-2026-44330CRITICAL free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-pfdmanagement route group without inbound OAuth2/bearer-token authori | May 27, 2026 | 10.0 | 34 | NO | NO |
CVE-2026-44315CRITICAL free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-pfd-management API without inbound OAuth2/bearer-token authorization. | May 27, 2026 | 9.4 | 32 | NO | NO |
CVE-2025-66719CRITICAL An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck() function in file internal/sbi/processor/access_token.go b | Jan 23, 2026 | 9.1 | 32 | NO | NO |
CVE-2026-44328HIGH free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound OAuth2 middleware. On top of th | May 27, 2026 | 8.2 | 31 | NO | NO |
CVE-2026-42083HIGH free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM poli | May 27, 2026 | 8.2 | 29 | NO | NO |
CVE-2025-66720HIGH Null pointer dereference in free5gc pcf 1.4.0 in file internal/sbi/processor/ampolicy.go in function HandleDeletePoliciesPolAssoId. | Jan 23, 2026 | 7.5 | 28 | NO | NO |
Signals from CVEs in this vendor scope (82 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Free5gc.
Media articles that mention a CVE ID that affects a product developed by Free5gc — matched by CVE ID, not by vendor name.