Denial of Service in free5GC NEF Component by Free5GC
CVE-2026-44319
7.5HIGH
What is CVE-2026-44319?
Prior to version 4.2.2, free5GC's NEF component had a vulnerability that could lead to a denial of service condition. When a notification URI specified in a PFD subscription is unreachable, it triggers a process termination. An attacker can exploit this by generating a malicious PFD subscription with a controlled notifyUri, causing the NEF process to exit during a PFD change notification. This results in the denial of service as the NEF's entire Service Based Interface (SBI) becomes unavailable until a restart. The issue has been addressed in version 4.2.2.
Affected Version(s)
free5gc < 4.2.2
