CVE-2026-1684: Free5GC SMF PFCP UDP Endpoint pfcp_reports.go HandleReports denial of service
A vulnerability was found in Free5GC SMF up to 4.1.0. Affected by this issue is the function HandleReports of the file /internal/context/pfcpreports.go of the component PFCP UDP Endpoint. The manipulation results in denial of service. The attack can be executed remotely. It is advisable to implement a patch to correct this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1684?
The severity of CVE-2026-1684 is classified as a denial of service vulnerability which can affect the Free5GC SMF component.
How do I fix CVE-2026-1684?
To fix CVE-2026-1684, upgrade Free5GC SMF to version 4.1.1 or later.
What component is affected by CVE-2026-1684?
CVE-2026-1684 affects the PFCP UDP Endpoint within the Free5GC SMF framework.
What versions of Free5GC SMF are vulnerable to CVE-2026-1684?
Free5GC SMF versions up to and including 4.1.0 are vulnerable to CVE-2026-1684.
What is the impact of CVE-2026-1684?
The impact of CVE-2026-1684 is a denial of service condition that can disrupt access to the PFCP UDP Endpoint.