CVE-2026-5661

MEDIUM

Free5GC NGSetupRequest denial of service

Title source: cna
STIX 2.1

Description

A vulnerability was identified in Free5GC 4.2.0. This affects an unknown function of the component NGSetupRequest Handler. Such manipulation leads to denial of service. The attack may be launched remotely. The exploit is publicly available and might be used.

References (7)

Core 7
Core References
Vdb Entry vdb-entry
VDB-355485 | Free5GC NGSetupRequest denial of service
https://vuldb.com/vuln/355485
Signature, Permissions Required signature permissions-required
VDB-355485 | CTI Indicators (IOB, IOC, TTP)
https://vuldb.com/vuln/355485/cti
Third Party Advisory third-party-advisory
Submit #785896 | Linux Foundation free5GC 4.2.0 State Synchronization Error
https://vuldb.com/submit/785896
Issue Tracking issue-tracking
https://github.com/free5gc/free5gc/issues/832
Patch issue-tracking patch
https://github.com/free5gc/amf/pull/201

Scores

CVSS v3 5.3
EPSS 0.0042
EPSS Percentile 33.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-404
Status published
Products (1)
None/Free5GC 4.2.0
Published Apr 06, 2026
Tracked Since Apr 06, 2026