CVE-2026-30653: High severity free5gc Free5GC AMF vulnerability
Published Mar 24, 2026
·Updated
An issue in Free5GC v.4.2.0 and before allows a remote attacker to cause a denial of service via the function HandleAuthenticationFailure of the component AMF
Affected Software
2 affected components
free5gc Free5GC AMF<=4.2.0
free5gc Free5gc<=4.2.0
Event History
Mar 24, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-30653?
CVE-2026-30653 is classified as a denial of service vulnerability affecting Free5GC versions up to 4.2.0.
2
How do I fix CVE-2026-30653?
To mitigate CVE-2026-30653, upgrade to Free5GC version 4.2.1 or later, which contains the fix.
3
What components are affected by CVE-2026-30653?
CVE-2026-30653 affects the AMF component of Free5GC versions 4.2.0 and earlier.
4
Can CVE-2026-30653 be exploited remotely?
Yes, CVE-2026-30653 can be exploited by a remote attacker to trigger a denial of service.
5
What action should I take if I cannot upgrade to a fixed version for CVE-2026-30653?
If you cannot upgrade, implement network security measures to limit access to the affected Free5GC systems.