CVE-2026-30050: Free5gc Free5gc vulnerability
Published Aug 27, 2026
·Updated
An issue in the ModifyAMFEventSubscriptionProcedure function (processor/eventexposure.go) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PATCH request.
Affected Software
1 affected component
free5gc Free5gc=4.1.0
Event History
Aug 27, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:17 PM
Description
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
An attacker needs to be able to send a crafted PATCH request to the affected event exposure functionality.
2
Which deployment versions are identified as affected?
The issue is reported in free5gc v4.1.0. No other affected or fixed versions are provided.
3
What is the impact of successful exploitation?
Successful exploitation can cause a denial of service through the ModifyAMFEventSubscriptionProcedure function in processor/event_exposure.go.