CVE-2026-1974: Free5GC SMF datapath.go ResolveNodeIdToIp denial of service
A vulnerability was identified in Free5GC up to 4.1.0. This affects the function ResolveNodeIdToIp of the file internal/sbi/processor/datapath.go of the component SMF. The manipulation leads to denial of service. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. It is recommended to apply a patch to fix this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1974?
CVE-2026-1974 is classified as a denial of service vulnerability in Free5GC SMF.
How do I fix CVE-2026-1974?
To address CVE-2026-1974, update Free5GC SMF to version 4.1.1 or later.
What components are affected by CVE-2026-1974?
CVE-2026-1974 affects the ResolveNodeIdToIp function in the SMF component of Free5GC up to version 4.1.0.
Can CVE-2026-1974 be exploited remotely?
Yes, CVE-2026-1974 can be exploited remotely, leading to denial of service.
What is the impact of CVE-2026-1974 on Free5GC?
CVE-2026-1974 can cause a denial of service, disrupting the operation of affected Free5GC installations.