CVE-2025-60638: High severity free5gc Free5gc vulnerability
Published Nov 24, 2025
·Updated
An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the NnssfNSSAIAvailability API.
Affected Software
4 affected componentsFixes available
free5gc Free5gc>=4.0.0<=4.0.1
go/github.com/free5gc/nssf<1.4.0
1.4.0
free5gc Free5gc=4.0.0
free5gc Free5gc=4.0.1
Event History
Nov 24, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·06:31 PM
Data Sourced
via GitHub·06:31 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-60638?
CVE-2025-60638 is a high-severity vulnerability that allows for denial of service.
2
How do I fix CVE-2025-60638?
To fix CVE-2025-60638, upgrade Free5GC to version 4.0.2 or higher.
3
What versions of Free5GC are affected by CVE-2025-60638?
Free5GC versions 4.0.0 and 4.0.1 are affected by CVE-2025-60638.
4
Can CVE-2025-60638 be exploited remotely?
Yes, CVE-2025-60638 can be exploited remotely through crafted POST requests.
5
What is the impact of CVE-2025-60638 on Free5GC?
The impact of CVE-2025-60638 on Free5GC is that it can lead to a denial of service condition.