Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Free5gc

First CVE: Oct 24, 2022Active for: 4 yearsTotal CVEs: 82
52.0
VTI Score
TOP TARGET

Free5gc is an open-source 5G core network implementation that, despite a narrow product portfolio, occupies a critical position in next-generation mobile infrastructure deployments and testing environments. The vendor's vulnerability footprint concentrates across its core service modules—including the Unified Data Management, Session Management Function, User Data Repository, and Policy Control Function components—and reflects the complexity inherent to distributed telecom protocol implementations and state management. The recurring weakness classes center on NULL-pointer dereferences, input-validation oversights, improper resource cleanup, authorization gaps, and sensitive-information leakage in error handling, which are characteristic of network-protocol parsers and service-to-service authentication boundaries in large-scale systems. Defenders operating 5G core infrastructure should monitor this vendor's releases closely and prioritize updates in internet-facing or untrusted-network deployments; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
82
Total CVEs
More Total CVEs than 99% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Free5gc over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 24, 2022
3 years ago
Most Recent CVE
May 27, 2026
59 days ago

Products(9 total)

Top CVEs

Signals from CVEs in this vendor scope (82 CVEs).

82 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-44327CRITICAL
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route group without inbound OAuth2/bearer-token authorization. A
May 27, 202610.036NONO
CVE-2026-44329CRITICAL
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without OAuth2/bearer-token authorization middl
May 27, 202610.035NONO
CVE-2022-38870HIGH
Free5gc v3.2.1 is vulnerable to Information disclosure.
Oct 25, 20227.535NOYES
CVE-2026-44326CRITICAL
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-traffic-influence API without inbound OAuth2/bearer-token authorizati
May 27, 20269.434NONO
CVE-2026-44330CRITICAL
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-pfdmanagement route group without inbound OAuth2/bearer-token authori
May 27, 202610.034NONO
CVE-2026-44315CRITICAL
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-pfd-management API without inbound OAuth2/bearer-token authorization.
May 27, 20269.432NONO
CVE-2025-66719CRITICAL
An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck() function in file internal/sbi/processor/access_token.go b
Jan 23, 20269.132NONO
CVE-2026-44328HIGH
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound OAuth2 middleware. On top of th
May 27, 20268.231NONO
CVE-2026-42083HIGH
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM poli
May 27, 20268.229NONO
CVE-2025-66720HIGH
Null pointer dereference in free5gc pcf 1.4.0 in file internal/sbi/processor/ampolicy.go in function HandleDeletePoliciesPolAssoId.
Jan 23, 20267.528NONO
View all 82 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products82 CVEs
24%
66%
9%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (2.4%)
Network79 (96.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.2%)
Attack Complexity
Low79 (96.3%)
High3 (3.7%)
Unknown0 (0.0%)
User Interaction
None80 (97.6%)
Unknown0 (0.0%)
Required2 (2.4%)
Privileges Required
Low8 (9.8%)
High0 (0.0%)
None74 (90.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (82 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.2% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Free5gc.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Free5gc — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Free5gc's Products

View all 4 CNAs →

Top CWEs