Access and Mobility Management Function Vulnerability in free5GC by free5GC
CVE-2026-41136

5.5MEDIUM

Key Information:

Vendor

Free5gc

Status
Vendor
CVE Published:
21 April 2026

What is CVE-2026-41136?

The Access & Mobility Management Function (AMF) component of free5GC is affected by a vulnerability in the HTTPUEContextTransfer handler located in internal/sbi/api_communication.go. Prior to version 1.4.3, when a request with an unsupported Content-Type is received, the absence of a default case in the switch statement results in the deserialization process being mistakenly skipped. This oversight allows for the invocation of the processor with an uninitialized UeContextTransferRequest object, potentially compromising the integrity of operations within the 5G mobile core network.

Affected Version(s)

amf < 1.4.3

References

CVSS V4

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.