Denial of Service Vulnerability in free5GC AUSF Authentication Server
CVE-2026-53551
6.9MEDIUM
What is CVE-2026-53551?
The free5GC AUSF (Authentication Server Function) prior to version 1.4.5 is susceptible to a denial of service attack due to improper validation of the supiOrSuci field in user equipment (UE) authentication requests. This vulnerability allows an unauthenticated attacker to send malformed requests containing null bytes or control characters that evade JSON parsing, causing subsequent requests to fail and resulting in an HTTP 500 'System failure'. The flaw can be exploited at scale, leading to denial of service for all subscribers attempting to authenticate through the compromised AUSF. This issue has been rectified in version 1.4.5.
Affected Version(s)
ausf < 1.4.5
free5gc < 4.2.2
