The number and severity of CVEs published that impact products developed by Mosaic5g over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-37229HIGH FlexRIC v2.0.0 contains a reachable assertion in e2ap_create_pdu() triggered when ASN.1 PER decoding fails. A remote unauthenticated attacker can send any non-PER byte sequence (e. | Jun 1, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-37228HIGH FlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/ep/e2ap_ep.c). The function allocates a fixed 32KB receive buffer and enforces assert(rc < len) on th | Jun 1, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-37226HIGH FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST referencing a non-existent E2 Node. The lookup function returns NULL, which is enforced by assert() in | Jun 1, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-37234HIGH FlexRIC v2.0.0 allows a single SCTP connection to bind multiple xapp_ids by sending multiple E42_SETUP_REQUESTs. On disconnect, only the first registered xapp_id's resources are cl | Jun 1, 2026 | 8.2 | 30 | NO | NO |
CVE-2026-37235HIGH FlexRIC v2.0.0 trusts the xapp_id field from E42 message payloads without binding it to the sender's SCTP association. The validation function valid_xapp_id() only checks that the | Jun 1, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-37233HIGH FlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation mechanism. The equality function eq_xapp_ric_gen_id() in src/ric/iApp/xapp_ric_id.c compares m0->xapp_i | Jun 1, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-37231HIGH FlexRIC v2.0.0 uses a uint16_t counter for xapp_id assignment but stores the value in uint32_t message fields. After 65,530+ E42_SETUP_REQUESTs, the 16-bit counter wraps around and | Jun 1, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-37230HIGH FlexRIC v2.0.0 crashes when the near-RT RIC receives a RIC_INDICATION message with a ran_func_id that does not exist in its registry. The lookup returns NULL, triggering assert() i | Jun 1, 2026 | 7.5 | 28 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mosaic5g.
Media articles that mention a CVE ID that affects a product developed by Mosaic5g — matched by CVE ID, not by vendor name.