Denial of Service Vulnerability in free5GC AUSF Authentication Server
CVE-2026-53551

6.9MEDIUM

Key Information:

Vendor

Free5gc

Vendor
CVE Published:
31 July 2026

What is CVE-2026-53551?

The free5GC AUSF (Authentication Server Function) prior to version 1.4.5 is susceptible to a denial of service attack due to improper validation of the supiOrSuci field in user equipment (UE) authentication requests. This vulnerability allows an unauthenticated attacker to send malformed requests containing null bytes or control characters that evade JSON parsing, causing subsequent requests to fail and resulting in an HTTP 500 'System failure'. The flaw can be exploited at scale, leading to denial of service for all subscribers attempting to authenticate through the compromised AUSF. This issue has been rectified in version 1.4.5.

Affected Version(s)

ausf < 1.4.5

free5gc < 4.2.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.