CVE-2026-1683

medium

Description

A vulnerability has been found in Free5GC SMF up to 4.1.0. Affected by this vulnerability is the function HandlePfcpSessionReportRequest of the file internal/pfcp/handler/handler.go of the component PFCP. The manipulation leads to denial of service. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. To fix this issue, it is recommended to deploy a patch.

References

https://vuldb.com/?submit.739654

https://vuldb.com/?submit.739653

https://vuldb.com/?id.343476

https://vuldb.com/?ctiid.343476

https://github.com/free5gc/smf/pull/188

https://github.com/free5gc/free5gc/issues/804#issue-3816086696

https://github.com/free5gc/free5gc/issues/804

Details

Source: Mitre, NVD

Published: 2026-01-30

Updated: 2026-01-30

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 5.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Severity: Medium

CVSS v4

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Severity: Medium