Denial of Service Vulnerability in free5GC by free5GC
CVE-2025-69232

2.7LOW

Key Information:

Vendor

Free5gc

Status
Vendor
CVE Published:
23 February 2026

What is CVE-2025-69232?

The free5GC project, which serves as an open-source solution for 5th generation (5G) mobile core networks, is susceptible to a vulnerability that arises from improper input validation and protocol compliance. Specifically, the versions of free5GC go-upf up to and including 1.2.6, along with corresponding free5GC smf versions up to and including 1.4.0, are affected. Attackers can exploit this vulnerability by sending malformed PFCP Association Setup Requests, which the User Plane Function (UPF) mistakenly accepts, leading to an inconsistent state. This disruption can cause legitimate requests to enter a reconnection loop with the Session Management Function (SMF) and degrade network services significantly. As of now, a patch is under development, and users are encouraged to apply it upon release for mitigation.

Affected Version(s)

go-upf <= 1.2.6

smf <= 1.4.0

References

CVSS V4

Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.