← Voltar à pesquisa de CVEs

CVE-2026-44325

free5GC

Descrição

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC-s NRF root SBI endpoint POST /oauth2/token contains a parser-level type-confusion bug family. The handler in NFs/nrf/internal/sbi/api_accesstoken.go reflects over models.NrfAccessTokenAccessTokenReq, special-cases only plain string and NrfNfManagementNfType fields, and treats every other field as if it were a single models.PlmnId. The parsed *models.PlmnId is then assigned with reflect.Value.Set() to whichever field name the attacker put in the form body, which panics whenever the destination field-s real type is incompatible (slice, different struct, primitive). Gin recovery converts each panic into HTTP 500, but the endpoint remains remotely panicable from a single unauthenticated form-encoded request and is repeatedly triggerable. This vulnerability is fixed in 4.2.2.

CVSS 7.5EPSS 0.394%Risco 0.78
Ver fonte
Publicação
2026-05-27 17:16:37
Versões afetadas
<4.2.2
Tipo
Core software
Vetor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H