SCA: security update for github.com/free5gc/nrf (GHSA-7c47-xr7q-p6hg)

high Tenable Self-Hosted Container Security Plugin ID 438976

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- free5GC is an open source 5G core network. free5GC NRF prior to version 1.4.2 has an Improper Input
Validation vulnerability leading to Denial of Service. All deployments of free5GC using the NRF discovery
service are affected. The `EncodeGroupId` function attempts to access array indices [0], [1], [2] without
validating the length of the split data. When the parameter contains insufficient separator characters,
the code panics with "index out of range". A remote attacker can cause the NRF service to panic and crash
by sending a crafted HTTP GET request with a malformed `group-id-list` parameter. This results in complete
denial of service for the NRF discovery service. free5GC NRF version 1.4.2 fixes the issue. There is no
direct workaround at the application level. The recommendation is to apply the provided patch or restrict
access to the NRF API to trusted sources only. (CVE-2026-33062)

Solution

Update the github.com/free5gc/nrf library and its related packages to version 1.4.2 or later.

See Also

https://github.com/advisories/GHSA-7c47-xr7q-p6hg

Plugin Details

Severity: High

ID: 438976

Version: Revision 1.10

Type: Local

Family: SCA Checks

Published: 3/19/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.73

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-33062

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 7.7

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/18/2026

Vulnerability Publication Date: 3/18/2026

Reference Information

CVE: CVE-2026-33062

cwe: CWE-284