CVE-2026-30067: Free5gc Free5gc vulnerability
An issue in the complexQueryFilterSubprocess function in the NRF Discovery service of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this denial-of-service issue?
Deployments running free5gc v4.0.1 with the NRF Discovery service are affected by the reported issue. The available information does not identify any affected versions other than v4.0.1.
What does an attacker need to do to trigger the issue?
An attacker must provide crafted input that reaches the complexQueryFilterSubprocess function in the NRF Discovery service. The provided information does not specify the required access level, endpoint, or authentication conditions.
What is the practical impact of successful exploitation?
Successful exploitation can cause a denial of service in the free5gc NRF Discovery service. No information is provided about data exposure, privilege escalation, or impact on other free5gc components.