Vulnerability Description
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound OAuth2 middleware. The POST /upi/v1/upNodesLinks create-or-update handler accepts attacker-controlled JSON and passes it directly into UpNodesFromConfiguration(), which calls logger.InitLog.Fatalf(...) on several validation failures. One confirmed path is the UE-IP-pool overlap check: a single unauthenticated POST that adds a new UPF whose pool overlaps an existing UPF terminates the entire SMF process (docker ps shows Exited (1)), not just the goroutine. This vulnerability is fixed in 4.2.2.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Free5Gc | Free5Gc | < 4.2.2 |
Related Weaknesses (CWE)
References
- https://github.com/free5gc/free5gc/issues/906ExploitIssue Tracking
- https://github.com/free5gc/free5gc/security/advisories/GHSA-44qj-cghf-9p97ExploitVendor Advisory
- https://github.com/free5gc/smf/commit/e0974e07ddab44a67d36a563cca383b2449e33e5Patch
- https://github.com/free5gc/smf/pull/203Issue TrackingPatch
- https://github.com/free5gc/free5gc/security/advisories/GHSA-44qj-cghf-9p97ExploitVendor Advisory
FAQ
What is CVE-2026-44321?
CVE-2026-44321 is a vulnerability with a CVSS score of 7.5 (HIGH). free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound OAuth2 middleware. The POST /upi/v1/upNodesLinks cr...
How severe is CVE-2026-44321?
CVE-2026-44321 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-44321?
Check the references section above for vendor advisories and patch information. Affected products include: Free5Gc Free5Gc.