CVE-2026-30060: Free5GC vulnerability
Published Aug 27, 2026
·Updated
An issue in free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) when parsing crafted SUCI data during UE registration.
Affected Software
1 affected component
Free5GC=4.0.1
Event History
Aug 27, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:17 PM
Description
Frequently Asked Questions
1
Which deployments are in scope?
Deployments using free5GC v4.0.1 are identified as affected. The vulnerable processing occurs when SUCI data is parsed during UE registration.
2
What input is required to trigger the issue?
An attacker must provide crafted SUCI data that reaches the UE registration parsing path.