CVE-2026-30058: Input Validation
Published Aug 27, 2026
·Updated
Improper Input Validation in the HTTPModifySubscription handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Affected Software
1 affected component
free5gc Free5gc=4.0.1
Event History
Aug 27, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:17 PM
Description
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
An attacker needs to send crafted input to the HTTPModifySubscription handler. The available information does not specify any authentication, network-access, or privilege requirements.
2
What is the likely impact of successful exploitation?
Successful exploitation can cause a denial of service in free5gc by triggering improper input validation in the HTTPModifySubscription handler.
3
Which version is identified as affected?
The reported affected version is free5gc v4.0.1.