Denial-of-Service Vulnerability in Free5GC Open-Source 5G Core Network
CVE-2026-42081

6.1MEDIUM

Key Information:

Vendor

Free5gc

Status
Vendor
CVE Published:
27 May 2026

What is CVE-2026-42081?

A vulnerability in Free5GC allows a malicious gNB to manipulate the AMF's stored UE security capabilities in NGAP PathSwitchRequest messages. The AMF does not verify these capabilities against its secure values, which may result in the delivery of incorrect information. Consequently, this exploitation can lead to persistent handover denial-of-service for affected User Equipment (UEs). This issue, which compromises the integrity of the handover process in a 5G network, is resolved in version 4.2.2 and emphasizes the necessity for proper verification of security capabilities.

Affected Version(s)

free5gc < 4.2.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.