CVE-2026-30057: High severity free5gc/CreateUEContext handler vulnerability
Published Aug 27, 2026
·Updated
An issue in the CreateUEContext handler component of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted request.
Affected Software
1 affected component
free5gc/CreateUEContext handler=4.1.0
Event History
Aug 27, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to do to trigger the denial of service?
An attacker needs to supply a crafted request to the CreateUEContext handler.
2
Which deployment components should be prioritized for review?
Prioritize systems running free5gc v4.1.0 that expose or use the CreateUEContext handler component.